Câu 22: 312-39V2: Certified SOC Analyst (CSA) v2
A major financial institution has strict policies preventing unauthorized data transfers. As a SOC analyst, you are conducting routine log analysis when you detect an anomaly – an employee's workstation is initiating large file transfers outside of business hours. The files in question contain highly sensitive custome…
Nội dung câu hỏi
A major financial institution has strict policies preventing unauthorized data transfers. As a SOC analyst, you are conducting routine log analysis when you detect an anomaly – an employee's workstation is initiating large file transfers outside of business hours. The files in question contain highly sensitive customer financial records. Upon further investigation, you discover that the employee has been remotely accessing the system from an unfamiliar IP address. Security logs also flag an unauthorized USB device connected to the workstation, violating corporate policy. Given the nature of the data involved and the possibility of data exfiltration, you need to act swiftly. What will be your first step in responding to this incident?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Isolate employee’s workstation and revoke remote access — đáp án hiện tại
- B. Conduct a full forensic analysis first
- C. Inform employee's department and wait for evidence
- D. Disable corporate VPN entirely
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.