Question 1 of 30
Quality control measures reveal that a critical server has been exhibiting anomalous network traffic patterns, suggesting a potential security breach. The security team is under pressure to quickly identify the source and scope of the threat to minimize potential damage. Which of the following actions represents the most appropriate and compliant initial response from a log analysis and monitoring perspective?
Immediately initiate a comprehensive collection and preservation of all relevant logs from affected systems and network devices, ensuring data integrity through hashing and secure storage, before commencing detailed analysis.
Prioritize isolating the suspected compromised server to prevent further malicious activity, deferring detailed log collection and analysis until the immediate threat is contained.
Focus analysis on readily accessible web server logs, assuming the anomaly is confined to web-based activity and ignoring logs from other server components or network devices.
Begin overwriting older log files to free up disk space and simplify the analysis process, focusing only on the most recent entries.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free