CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 3: Google Cloud Professional Security Operations Engineer

You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial transactions, shows signs of unauthorized file changes and network scanning from a suspicious IP address. You suspect tha…

Nội dung câu hỏi

You are an incident responder at your organization using Google Security Operations (SecOps) for monitonng and investigation. You discover that a critical production server, which handles financial transactions, shows signs of unauthorized file changes and network scanning from a suspicious IP address. You suspect that persistence mechanisms may have been installed. You need to use Google SecOps to immediately contain the threat while ensuring that forensic data remains available for investigation. What should you do first?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Use the firewall integration to submit the IP address to a network block list to inhibit internet access from that machine.
  2. B. Deploy emergency patches, and reboot the server to remove malicious persistence.
  3. C. Use the EDR integration to quarantine the compromised asset. — đáp án hiện tại
  4. D. Use VirusTotal to enrich the IP address and retrieve the domain. Add the domain to the proxy block list.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề