nerdexam
ExamsGCIHQuestions#509
GIAC

GCIH · Question #509

GCIH Question #509: Real Exam Question with Answer & Explanation

Sign in or unlock GCIH to reveal the answer and full explanation for question #509. The question stem and answer options stay visible for context.

Malware Analysis & Advanced Persistent Threats

Question

Which of the following would be a recommended containment measure taken to prevent a bot infected system from communicating over command and control channels?

Options

  • AConfiguring a host IPS to block incoming web traffic
  • BUpdating the system to the current patch level
  • CSetting an egress firewall rule at the host's subnet perimeter
  • DChanging the system's DNS pointer to a different IP address

Unlock GCIH to see the answer

You've previewed enough free GCIH questions. Unlock GCIH for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#botnet C2#egress firewall#containment measures#network-level blocking
Full GCIH Practice