nerdexam
CompTIA

220-1102 · Question #623

A user clicked a link in an email, and now the cursor is moving around on its own. A technician notices that File Explorer is open and data is being copied from the local drive to an unknown cloud…

The correct answer is D. Quarantine the workstation. When a user's computer exhibits signs of active compromise, such as data exfiltration, the technician should first quarantine the workstation.

Security

Question

A user clicked a link in an email, and now the cursor is moving around on its own. A technician notices that File Explorer is open and data is being copied from the local drive to an unknown cloud storage location. Which of the following should the technician do first?

Options

  • AInvestigate the reported symptoms.
  • BRun anti-malware software.
  • CEducate the user about dangerous links.
  • DQuarantine the workstation.

How the community answered

(62 responses)
  • A
    3% (2)
  • B
    13% (8)
  • C
    8% (5)
  • D
    76% (47)

Why each option

When a user's computer exhibits signs of active compromise, such as data exfiltration, the technician should first quarantine the workstation.

AInvestigate the reported symptoms.

Investigating the reported symptoms is important, but it should happen after the immediate threat of spread or further damage has been contained by quarantining the device.

BRun anti-malware software.

Running anti-malware software is part of the eradication phase, which comes after containment to remove the threat, not as the initial response when active data copying is observed.

CEducate the user about dangerous links.

Educating the user about dangerous links is a crucial preventative and post-incident measure, but it does not address the immediate, active security incident unfolding on the workstation.

DQuarantine the workstation.Correct

Quarantining the workstation by disconnecting it from the network is the critical first step in incident response to prevent the malware from spreading to other systems and to stop further data exfiltration from the compromised machine.

Concept tested: Incident response - containment

Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final

Topics

#Incident Response#Malware#Data Exfiltration#Containment

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice