nerdexam
Cisco

100-160 · Question #49

During an incident response, the security team needs to isolate a compromised server from the rest of the network but still allow forensic analysis. Which action should they take?

The correct answer is B. Disconnect the server from the network and connect it to an isolated forensic network. Containment often involves removing an affected system from the production network and connecting it to a controlled forensic environment to preserve evidence and prevent further

Cybersecurity Incident Response

Question

During an incident response, the security team needs to isolate a compromised server from the rest of the network but still allow forensic analysis. Which action should they take?

Options

  • APower off the server immediately.
  • BDisconnect the server from the network and connect it to an isolated forensic network.
  • CDelete suspicious files from the server.
  • DReset all user passwords on the server.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    84% (27)
  • C
    9% (3)
  • D
    3% (1)

Explanation

Containment often involves removing an affected system from the production network and connecting it to a controlled forensic environment to preserve evidence and prevent further

Topics

#server isolation#forensic analysis#incident containment#compromised host

Community Discussion

No community discussion yet for this question.

Full 100-160 Practice