Question 1 of 30
Stakeholder feedback indicates a significant increase in unusual network traffic patterns originating from a critical server hosting sensitive customer data. Initial automated alerts suggest a potential unauthorized access attempt. What is the most appropriate immediate course of action for the security operations team?
Activate the established incident response plan, beginning with an initial assessment and containment strategy for the affected server.
Immediately shut down the critical server to prevent any further potential data exfiltration.
Delete all suspicious files and logs on the server to remove any evidence of the intrusion.
Forward all alert data to senior management and await their directive on how to proceed.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free