Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 135 Topic 14 Discussion

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 135 Topic 14 Discussion

CS0-003 Exam Topic 14 Question 135 Discussion:
Question #: 135
Topic #: 14

A cybersecurity team quarantines a virtual machine (VM) that has triggered alerts. However, this action does not stop the threat. Similar alerts are occurring for other VMs in the same broadcast domain. Which of the following steps in the incident response process should the team take next?


A.

Escalate the incident to the Chief Information Security Officer and request approval to notify the legal department.


B.

Switch back to the analysis phase and gather additional data.


C.

Move to the eradication phase and begin deleting suspicious files.


D.

Continue with the containment phase and isolate the subnet.


Get Premium CS0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.