Question 1 of 30
System analysis indicates a series of unusual outbound network connections from several workstations to an unknown external IP address, coupled with a noticeable slowdown in system performance across the affected machines. Which of the following initial threat classifications and corresponding response strategies is the most professionally sound and efficient?
Classify the activity as a potential malware infection, focusing initial containment efforts on isolating the affected workstations from the network and initiating a malware scan on those systems.
Immediately classify the activity as a sophisticated denial-of-service (DoS) attack and begin rerouting all network traffic through a scrubbing service.
Assume the activity is a result of a misconfigured network device and focus on reviewing network device configurations.
Classify the activity as a phishing campaign and initiate a company-wide email security awareness training session.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free