An incident handler is assigned to initiate an incident response for a complex network that has been affected by malware. Which of the following actions should be taken FIRST?
C. Isolate devices from the network
This is the first priority to contain the malware and prevent it from spreading to other systems.
Incorrect Responses:
A. Make an incident response plan
Important, but should already be in place before incidents. Not a first step during an active infection.
B. Prepare incident response tools
Necessary, but preparing tools during the incident wastes time. They should be ready beforehand.
D. Capture network traffic for analysis
Useful for investigation, but analysis comes after containment to avoid further spreading of malware.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
044f354
1 month, 3 weeks ago