SY0-501 · Question #166
Simulation A security administrator discovers that an attack has been completed against a node on the corporate network. All available logs were collected and stored. You must review all network logs
Sign in or unlock SY0-501 to reveal the answer and full explanation for question #166. The question stem and answer options stay visible for context.
Question
Simulation A security administrator discovers that an attack has been completed against a node on the corporate network. All available logs were collected and stored. You must review all network logs to discover the scope of the attack, check the box of the node(s) that have been compromised and drag and drop the appropriate actions to complete the incident response on the network. The environment is a critical production environment; perform the LEAST disruptive actions on the network, while still performing the appropriate incid3nt responses. Instructions: The web server, database server, IDS, and User PC are clickable. Check the box of the node(s) that have been compromised and drag and drop the appropriate actions to complete the incident response on the network. Not all actions may be used, and order is not important. If at anytime you would like to bring back the initial state of the simulation, please select the Reset button. When you have completed the simulation, please select the Done button to submit. Once the simulation is submitted, please select the Next button to continue. Answer:
Database server was attacked, actions should be to capture network traffic and Chain of Custody. IDS Server Log:
Web Server Log:
Database Server Log:
Users PC Log:
Exhibits
Unlock SY0-501 to see the answer
You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.







