ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 60 - SY0-601 discussion

Report
Export

A security analyst is responding to an alert from the SIEM. The alert states that malware was discovered on a host and was not automatically deleted. Which of the following would be BEST for the analyst to perform?

A.
Add a deny-all rule to that host in the network ACL
Answers
A.
Add a deny-all rule to that host in the network ACL
B.
Implement a network-wide scan for other instances of the malware.
Answers
B.
Implement a network-wide scan for other instances of the malware.
C.
Quarantine the host from other parts of the network
Answers
C.
Quarantine the host from other parts of the network
D.
Revoke the client's network access certificates
Answers
D.
Revoke the client's network access certificates
Suggested answer: C

Explanation:

When malware is discovered on a host, the best course of action is to quarantine the host from other parts of the network. This prevents the malware from spreading and potentially infecting other hosts. Adding a deny-all rule to the host in the network ACL may prevent legitimate traffic from being processed, implementing a network-wide scan is time-consuming and may not be necessary, and revoking the client's network access certificates is an extreme measure that may not be warranted.

Reference: CompTIA Security+ Study Guide, pages 113-114

asked 02/10/2024
Harri Jaakkonen
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first