CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 5: 350-201: Performing CyberOps Using Core Security Technologies (CBRCOR)

A payroll administrator noticed unexpected changes within a piece of software and reported the incident to the incident response team. Which actions should be taken at this step in the incident response workflow?

Nội dung câu hỏi

A payroll administrator noticed unexpected changes within a piece of software and reported the incident to the incident response team. Which actions should be taken at this step in the incident response workflow?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Classify the criticality of the information, research the attacker's motives, and identify missing patches
  2. B. Determine the damage to the business, extract reports, and save evidence according to a chain of custody
  3. C. Classify the attack vector, understand the scope of the event, and identify the vulnerabilities being exploited — đáp án hiện tại
  4. D. Determine the attack surface, evaluate the risks involved, and communicate the incident according to the escalation plan

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề