350-201 · Question #70
The incident response team receives information about the abnormal behavior of a host. A malicious file is found being executed from an external USB flash drive. The team collects and documents all…
The correct answer is B. Isolate the infected host from the rest of the subnet. Short-term containment - limiting damage before the incident gets worse, usually by isolating network segments, taking down hacked production server and routing to failover.
Question
The incident response team receives information about the abnormal behavior of a host. A malicious file is found being executed from an external USB flash drive. The team collects and documents all the necessary evidence from the computing resource. What is the next step?
Options
- AConduct a risk assessment of systems and applications
- BIsolate the infected host from the rest of the subnet
- CInstall malware prevention software on the host
- DAnalyze network traffic on the host's subnet
How the community answered
(22 responses)- A5% (1)
- B91% (20)
- D5% (1)
Explanation
Short-term containment - limiting damage before the incident gets worse, usually by isolating network segments, taking down hacked production server and routing to failover.
Topics
Community Discussion
No community discussion yet for this question.