Cisco
100-160 · Question #49
During an incident response, the security team needs to isolate a compromised server from the rest of the network but still allow forensic analysis. Which action should they take?
The correct answer is B. Disconnect the server from the network and connect it to an isolated forensic network. Containment often involves removing an affected system from the production network and connecting it to a controlled forensic environment to preserve evidence and prevent further
Cybersecurity Incident Response
Question
During an incident response, the security team needs to isolate a compromised server from the rest of the network but still allow forensic analysis. Which action should they take?
Options
- APower off the server immediately.
- BDisconnect the server from the network and connect it to an isolated forensic network.
- CDelete suspicious files from the server.
- DReset all user passwords on the server.
How the community answered
(32 responses)- A3% (1)
- B84% (27)
- C9% (3)
- D3% (1)
Explanation
Containment often involves removing an affected system from the production network and connecting it to a controlled forensic environment to preserve evidence and prevent further
Topics
#server isolation#forensic analysis#incident containment#compromised host
Community Discussion
No community discussion yet for this question.