Cisco Performing CyberOps Using Core Security Technologies (CBRCOR) 350-201 Question # 37 Topic 4 Discussion

Cisco Performing CyberOps Using Core Security Technologies (CBRCOR) 350-201 Question # 37 Topic 4 Discussion

350-201 Exam Topic 4 Question 37 Discussion:
Question #: 37
Topic #: 4

An engineer detects an intrusion event inside an organization’s network and becomes aware that files that contain personal data have been accessed. Which action must be taken to contain this attack?


A.

Disconnect the affected server from the network.


B.

Analyze the source.


C.

Access the affected server to confirm compromised files are encrypted.


D.

Determine the attack surface.


Get Premium 350-201 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.