ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 79 - SY0-601 discussion

Report
Export

The SIEM at an organization has detected suspicious traffic coming a workstation in its internal network. An analyst in the SOC the workstation and discovers malware that is associated with a botnet is installed on the device A review of the logs on the workstation reveals that the privileges of the local account were escalated to a local administrator. To which of the following groups should the analyst report this real-world event?

A.
The NOC team
Answers
A.
The NOC team
B.
The vulnerability management team
Answers
B.
The vulnerability management team
C.
The CIRT
Answers
C.
The CIRT
D.
The read team
Answers
D.
The read team
Suggested answer: C

Explanation:

The Computer Incident Response Team (CIRT) is responsible for handling incidents and ensuring that the incident response plan is followed. Reference: CompTIA Security+ Study Guide, Exam SY0-601, Chapter 9

asked 02/10/2024
Lukas Reker
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first