Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

CompTIA SecurityX Certification Exam CAS-005 Question # 99 Topic 10 Discussion

CompTIA SecurityX Certification Exam CAS-005 Question # 99 Topic 10 Discussion

CAS-005 Exam Topic 10 Question 99 Discussion:
Question #: 99
Topic #: 10

During an incident response activity, the response team collected some artifacts from a compromised server, but the following information is missing:

• Source of the malicious files

• Initial attack vector

• Lateral movement activities

The next step in the playbook is to reconstruct a timeline. Which of the following best supports this effort?


A.

Executing decompilation of binary files


B.

Analyzing all network routes and connections


C.

Performing primary memory analysis


D.

Collecting operational system logs and storage disk data


Get Premium CAS-005 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.