Question 1 of 30
Market research demonstrates an increasing sophistication in advanced persistent threats (APTs) targeting financial institutions. Your organization has detected anomalous network traffic patterns originating from an internal segment, suggesting a potential APT incursion. As a senior security analyst, you are tasked with initiating a threat hunt to identify the scope and nature of this potential compromise. Which of the following actions represents the most responsible and compliant approach to begin this investigation?
Immediately initiate a broad data collection and analysis of all network logs and endpoint telemetry within the affected segment, cross-referencing with known threat intelligence indicators, while documenting all actions for later review.
Begin by reviewing the organization's data privacy policies and relevant legal guidelines concerning data access and user privacy to define the permissible scope and methods for the threat hunt.
Deploy advanced network intrusion detection system (NIDS) sensors across the entire network to capture all traffic for immediate deep packet inspection, prioritizing threat identification over data access protocols.
Conduct an immediate, in-depth forensic analysis of the most critical servers in the affected segment, assuming a high likelihood of compromise and prioritizing the recovery of sensitive data.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free