nerdexam
Dell-EMC

D-CSF-SC-01 · Question #89

The network security team in your company has discovered a threat that leaked partial data on a compromised file server that handles sensitive information. Containment must be initiated and…

The correct answer is C. Restart the server to purge all malicious connections and keep it powered on for further analysis. See the full explanation below for the reasoning.

Question

The network security team in your company has discovered a threat that leaked partial data on a compromised file server that handles sensitive information. Containment must be initiated and addresses by the CSIRT. Service disruption is not a concern because this server is used only to store files and does not hold any critical workload. Your company security policy required that all forensic information must be preserved. Which actions should you take to stop data leakage and comply with requirements of the company security policy?

Options

  • ADisconnect the file server from the network to stop data leakage and keep it powered on for further
  • BShut down the server to stop the data leakage and power it up only for further forensic analysis.
  • CRestart the server to purge all malicious connections and keep it powered on for further analysis.
  • DCreate a firewall rule to block all external connections for this file server and keep it powered on for

How the community answered

(60 responses)
  • A
    7% (4)
  • B
    10% (6)
  • C
    80% (48)
  • D
    3% (2)

Community Discussion

No community discussion yet for this question.

Full D-CSF-SC-01 Practice