ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 309 - SY0-601 discussion

Report
Export

A systems engineer thinks a business system has been compromised and is being used to exfiltrated data to a competitor The engineer contacts the CSIRT The CSIRT tells the engineer to immediately disconnect the network cable and to not do anything else Which of the following is the most likely reason for this request?

A.
The CSIRT thinks an insider threat is attacking the network
Answers
A.
The CSIRT thinks an insider threat is attacking the network
B.
Outages of business-critical systems cost too much money
Answers
B.
Outages of business-critical systems cost too much money
C.
The CSIRT does not consider the systems engineer to be trustworthy
Answers
C.
The CSIRT does not consider the systems engineer to be trustworthy
D.
Memory contents including fileles malware are lost when the power is turned off
Answers
D.
Memory contents including fileles malware are lost when the power is turned off
Suggested answer: D

Explanation:

Memory contents including files and malware are lost when the power is turned off. This is because memory is a volatile storage device that requires constant power to retain data. If a system has been compromised and is being used to exfiltrate data to a competitor, the CSIRT may want to preserve the memory contents for forensic analysis and evidence collection. Therefore, the CSIRT may tell the engineer to immediately disconnect the network cable and not do anything else to prevent further data loss or tampering.

Reference: https://www.comptia.org/certifications/security#examdetails https://www.comptia.org/content/guides/comptia-security-sy0-601-exam-objectives https://resources.infosecinstitute.com/topic/memory-acquisition-and-analysis/

asked 02/10/2024
Bianca Duizer
48 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first