nerdexam
CompTIA

CV0-004 · Question #24

A security analyst confirms a zero-day vulnerability was exploited by hackers who gained access to confidential customer data and installed ransomware on the server Which of the following steps…

The correct answer is D. Inform the management and legal teams about the data breach F. Modify the firewall rules to block the IP addresses and update the ports. Inform the management and legal teams about the data breach: Incident response best practices and legal/regulatory requirements (like GDPR) mandate that management and legal teams are informed promptly following a data breach. This allows the organization to initiate…

Security

Question

A security analyst confirms a zero-day vulnerability was exploited by hackers who gained access to confidential customer data and installed ransomware on the server Which of the following steps should the security analyst take? (Choose two.)

Options

  • AContact the customers to inform them about the data breach.
  • BContact the hackers to negotiate payment lo unlock the server.
  • CSend a global communication to inform all impacted users.
  • DInform the management and legal teams about the data breach
  • EDelete confidential data used on other servers that might be compromised.
  • FModify the firewall rules to block the IP addresses and update the ports.

How the community answered

(62 responses)
  • A
    2% (1)
  • B
    5% (3)
  • C
    10% (6)
  • D
    82% (51)
  • E
    2% (1)

Explanation

Inform the management and legal teams about the data breach: Incident response best practices and legal/regulatory requirements (like GDPR) mandate that management and legal teams are informed promptly following a data breach. This allows the organization to initiate appropriate communication plans, understand legal obligations, and coordinate the overall Modify the firewall rules to block the IP addresses and update the ports: This is a critical containment step in the incident response process. Blocking the malicious IP addresses and closing the exploited ports helps to prevent further unauthorized access and stop the spread of the ransomware or data exfiltration, thus limiting the impact of the incident.

Topics

#incident response#data breach#ransomware#network security

Community Discussion

No community discussion yet for this question.

Full CV0-004 Practice