Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

ECCouncil EC Council Certified Incident Handler (ECIH v3) 212-89 Question # 28 Topic 3 Discussion

ECCouncil EC Council Certified Incident Handler (ECIH v3) 212-89 Question # 28 Topic 3 Discussion

212-89 Exam Topic 3 Question 28 Discussion:
Question #: 28
Topic #: 3

Lena, a SOC analyst, observes a pattern of unusual login attempts originating from multiple foreign IP addresses tied to shared drive links circulating within the organization. These links were embedded in emails appearing to come from the HR department and marked with urgent subject lines. Upon deeper inspection, Lena finds multiple similar messages still pending in the mail server’s delivery queue. To prevent widespread exposure, she takes immediate action to eliminate these messages before they reach employees' inboxes. Which incident response action best describes Lena’s action?


A.

Preemptively purging queued phishing emails from the server


B.

Flagging login anomalies for correlation in the SIEM


C.

Initiating forensic triage on suspicious attachments


D.

Isolating compromised mailboxes from the email relay


Get Premium 212-89 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.