CAS-005 · Question #498
During an incident response activity, the response team collected some artifacts from a compromised server, but the following information is missing: - Source of the malicious files - Initial attack v
The correct answer is D. Collecting operational system logs and storage disk data. Collecting operating system logs and storage disk data provides historical records of file creation, modifications, user activity, and system events. These artifacts are essential for reconstructing a detailed timeline of the attack, including the source of malicious files, initi
Question
During an incident response activity, the response team collected some artifacts from a compromised server, but the following information is missing:
- Source of the malicious files
- Initial attack vector
- Lateral movement activities
The next step in the playbook is to reconstruct a timeline. Which of the following best supports this effort?
Options
- AExecuting decompilation of binary files
- BAnalyzing all network routes and connections
- CPerforming primary memory analysis
- DCollecting operational system logs and storage disk data
How the community answered
(19 responses)- A5% (1)
- B16% (3)
- C5% (1)
- D74% (14)
Explanation
Collecting operating system logs and storage disk data provides historical records of file creation, modifications, user activity, and system events. These artifacts are essential for reconstructing a detailed timeline of the attack, including the source of malicious files, initial entry, and lateral
Community Discussion
No community discussion yet for this question.