ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 480 - SY0-601 discussion

Report
Export

An analyst is working on an email security incident in which the target opened an attachment containing a worm. The analyst wants to Implement mitigation techniques to prevent further spread. Which of the following is the best course of action for the analyst to take?

A.
Apply a DLP solution.
Answers
A.
Apply a DLP solution.
B.
Implement network segmentation.
Answers
B.
Implement network segmentation.
C.
Utilize email content filtering.
Answers
C.
Utilize email content filtering.
D.
Isolate the infected attachment.
Answers
D.
Isolate the infected attachment.
Suggested answer: D

Explanation:

Isolating the infected attachment is the best course of action for the analyst to take to prevent further spread of the worm. A worm is a type of malware that can self-replicate and infect other devices without human interaction. By isolating the infected attachment, the analyst can prevent the worm from spreading to other devices or networks via email, file-sharing, or other means. Isolating the infected attachment can also help the analyst to analyze the worm and determine its source, behavior, and impact.

Reference:

https://www.security.org/antivirus/computer-worm/

https://sec.cloudapps.cisco.com/security/center/resources/worm_mitigation_whitepaper.html

asked 02/10/2024
Angelo Gulisano
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first