List of questions
Related questions
Question 11 - SY0-601 discussion
During an incident a company CIRT determine it is necessary to observe the continued network- based transaction between a callback domain and the malware running on an enterprise PC. Which of the following techniques would be BEST to enable this activity while reducing the risk of lateral spread and the risk that the adversary would notice any changes?
A.
Physical move the PC to a separate internet pint of presence
B.
Create and apply micro segmentation rules.
C.
Emulate the malware in a heavily monitored DM Z segment.
D.
Apply network blacklisting rules for the adversary domain
Your answer:
0 comments
Sorted by
Leave a comment first