ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 354 - SY0-601 discussion

Report
Export

An analyst is working on an investigation with multiple alerts for multiple hosts. The hosts are showing signs of being compromised by a fast-spreading worm. Which of the following should be the next step in order to stop the spread?

A.
Disconnect every host from the network.
Answers
A.
Disconnect every host from the network.
B.
Run an AV scan on the entire
Answers
B.
Run an AV scan on the entire
C.
Scan the hosts that show signs of
Answers
C.
Scan the hosts that show signs of
D.
Place all known-infected hosts on an isolated network
Answers
D.
Place all known-infected hosts on an isolated network
Suggested answer: D

Explanation:

Placing all known-infected hosts on an isolated network is the best way to stop the spread of a worm infection. This will prevent the worm from reaching other hosts on the network and allow the infected hosts to be cleaned and restored. Disconnecting every host from the network is not practical and may disrupt business operations. Running an AV scan on the entire network or scanning the hosts that show signs of infection may not be effective or fast enough to stop a fast-spreading worm.

asked 02/10/2024
jordi vanderpooten
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first