CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 24 Topic 3 Discussion

CompTIA CyberSecurity Analyst CySA+ Certification Exam CS0-003 Question # 24 Topic 3 Discussion

CS0-003 Exam Topic 3 Question 24 Discussion:
Question #: 24
Topic #: 3

A security analyst discovers an ongoing ransomware attack while investigating a phishing email. The analyst downloads a copy of the file from the email and isolates the affected workstation from the network. Which of the following activities should the analyst perform next?


A.

Wipe the computer and reinstall software


B.

Shut down the email server and quarantine it from the network.


C.

Acquire a bit-level image of the affected workstation.


D.

Search for other mail users who have received the same file.


Get Premium CS0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.