ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 283 - SY0-701 discussion

Report
Export

A cybersecurity incident response team at a large company receives notification that malware is present on several corporate desktops No known Indicators of compromise have been found on the network. Which of the following should the team do first to secure the environment?

A.
Contain the Impacted hosts
Answers
A.
Contain the Impacted hosts
B.
Add the malware to the application blocklist.
Answers
B.
Add the malware to the application blocklist.
C.
Segment the core database server.
Answers
C.
Segment the core database server.
D.
Implement firewall rules to block outbound beaconing
Answers
D.
Implement firewall rules to block outbound beaconing
Suggested answer: A

Explanation:

The first step in responding to a cybersecurity incident, particularly when malware is detected, is to contain the impacted hosts. This action prevents the spread of malware to other parts of the network, limiting the potential damage while further investigation and remediation actions are planned.

Reference = CompTIA Security+ SY0-701 study materials, particularly on incident response procedures and the importance of containment in managing security incidents.

asked 02/10/2024
Test Test
25 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first