300-215 · Question #111
A security team detected an above-average amount of inbound tcp/135 connection attempts from unidentified senders. The security team is responding based on their incident response playbook. Which…
The correct answer is C. centralized user management D. intrusion prevention system. The eradication phase in incident response involves eliminating the root cause of the incident and strengthening defenses to prevent reoccurrence. In this case: Intrusion Prevention System (D): Adding new rules to the IPS to detect and block malicious activity on TCP/135 is a…
Question
A security team detected an above-average amount of inbound tcp/135 connection attempts from unidentified senders. The security team is responding based on their incident response playbook. Which two elements are part of the eradication phase for this incident? (Choose two.)
Options
- Aanti-malware software
- Bdata and workload isolation
- Ccentralized user management
- Dintrusion prevention system
- Eenterprise block listing solution
How the community answered
(35 responses)- A6% (2)
- B3% (1)
- C83% (29)
- E9% (3)
Explanation
The eradication phase in incident response involves eliminating the root cause of the incident and strengthening defenses to prevent reoccurrence. In this case: Intrusion Prevention System (D): Adding new rules to the IPS to detect and block malicious activity on TCP/135 is a direct eradication step to remove the threat's entry point and prevent Centralized User Management (C): Hardening user accounts, removing unnecessary permissions, and applying tighter authentication/authorization measures helps eliminate the possibility that threat actors could exploit weak or mismanaged accounts to continue accessing
Topics
Community Discussion
No community discussion yet for this question.