Question 1 of 30
Implementation of a rapid cybersecurity incident response plan is underway following the discovery of a sophisticated malware infection that has potentially accessed sensitive customer financial data. The security analyst must decide on the immediate containment strategy. Which of the following approaches best balances the need for swift action with the protection of customer privacy and regulatory compliance?
Isolate affected network segments and systems to prevent further lateral movement of the malware, while simultaneously initiating secure forensic imaging and backups of compromised systems to preserve evidence and data.
Immediately wipe and re-image all potentially affected servers and workstations to ensure complete eradication of the malware, regardless of data preservation needs.
Halt all containment efforts until a comprehensive, pre-incident level risk assessment of every possible data exfiltration vector can be completed.
Implement aggressive network segmentation that may temporarily expose limited amounts of sensitive data to prevent the malware from spreading further, prioritizing speed of containment above all else.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free