CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 4: GCED: GIAC Certified Enterprise Defender

An incident response team is handling a worm infection among their user workstations. They created an IPS signature to detect and block worm activity on the border IPS, then removed the worms artifacts or workstations triggering the rule. Despite this action, worm activity continued for days after. Where did the incid…

Nội dung câu hỏi

An incident response team is handling a worm infection among their user workstations. They created an IPS signature to detect and block worm activity on the border IPS, then removed the worms artifacts or workstations triggering the rule. Despite this action, worm activity continued for days after. Where did the incident response team fail?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. The team did not adequately apply lessons learned from the incident
  2. B. The custom rule did not detect all infected workstations — đáp án hiện tại
  3. C. They did not receive timely notification of the security event
  4. D. The team did not understand the worm’s propagation method

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề