ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 315 - SY0-601 discussion

Report
Export

A security analyst receives an alert that indicates a user's device is displaying anomalous behavior The analyst suspects the device might be compromised Which of the following should the analyst to first?

A.
Reboot the device
Answers
A.
Reboot the device
B.
Set the host-based firewall to deny an incoming connection
Answers
B.
Set the host-based firewall to deny an incoming connection
C.
Update the antivirus definitions on the device
Answers
C.
Update the antivirus definitions on the device
D.
Isolate the device
Answers
D.
Isolate the device
Suggested answer: D

Explanation:

Isolating the device is the first thing that a security analyst should do if they suspect that a user’s device might be compromised. Isolating the device means disconnecting it from the network or placing it in a separate network segment to prevent further communication with potential attackers or malicious hosts. Isolating the device can help contain the incident, limit the damage or data loss, preserve the evidence, and facilitate the investigation and remediation.

Reference: https://www.comptia.org/certifications/security#examdetails https://www.comptia.org/content/guides/comptia-security-sy0-601-exam-objectives https://resources.infosecinstitute.com/topic/incident-response-process/

asked 02/10/2024
Yves ADINGNI
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first