List of questions
Related questions
Question 267 - CS0-003 discussion
A web application team notifies a SOC analyst that there are thousands of HTTP/404 events on the public-facing web server. Which of the following is the next step for the analyst to take?
A.
Instruct the firewall engineer that a rule needs to be added to block this external server.
B.
Escalate the event to an incident and notify the SOC manager of the activity.
C.
Notify the incident response team that a DDoS attack is occurring.
D.
Identify the IP/hostname for the requests and look at the related activity.
Your answer:
0 comments
Sorted by
Leave a comment first