Question 1 of 30
The performance metrics show a significant increase in unauthorized outbound network traffic originating from a critical customer database server. As the lead security analyst, you must initiate the incident response process. Which of the following actions best aligns with regulatory compliance and professional incident response best practices?
Immediately isolate the affected server from the network to prevent further data exfiltration, initiate forensic imaging of the server and relevant logs, and engage legal counsel and the compliance officer to determine notification obligations.
Wipe and rebuild the affected server immediately to restore normal operations and prevent any further unauthorized access.
Halt all remediation efforts until a complete forensic analysis of the server and network traffic can be performed, which may take several days.
Focus solely on blocking the unauthorized outbound traffic at the firewall and monitor the situation without immediate server isolation or evidence preservation.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free