300-215 · Question #24
A security team received reports of users receiving emails linked to external or unknown URLs that are non-returnable and non-deliverable. The ISP also reported a 500% increase in the amount of…
The correct answer is D. remove vulnerabilities E. scan hosts with updated signatures. In the recovery phase, the goal is to restore affected systems to normal operations and ensure the threat has been completely eradicated. This phase may include restoring data from clean backups, replacing compromised systems, and the re-installation of the Operating System…
Question
A security team received reports of users receiving emails linked to external or unknown URLs that are non-returnable and non-deliverable. The ISP also reported a 500% increase in the amount of ingress and egress email traffic received. After detecting the problem, the security team moves to the recovery phase in their incident response plan. Which two actions should be taken in the recovery phase of this incident? (Choose two.)
Options
- Averify the breadth of the attack
- Bcollect logs
- Crequest packet capture
- Dremove vulnerabilities
- Escan hosts with updated signatures
How the community answered
(42 responses)- A14% (6)
- B2% (1)
- C7% (3)
- D76% (32)
Explanation
In the recovery phase, the goal is to restore affected systems to normal operations and ensure the threat has been completely eradicated. This phase may include restoring data from clean backups, replacing compromised systems, and the re-installation of the Operating System (OS) and applications. During recovery, scanning hosts with updated antivirus and removing vulnerabilities ensures systems do not get reinfected.
Topics
Community Discussion
No community discussion yet for this question.