Question 1 of 30
System analysis indicates a potential data breach involving sensitive customer information stored on a web server. The security analyst has confirmed unauthorized access and suspects data exfiltration. Given the urgency and the potential for significant regulatory penalties under frameworks like the GDPR, what is the most appropriate immediate course of action?
Immediately isolate the affected server from the network to prevent further unauthorized access and data loss, and then activate the organization's incident response plan.
Attempt to quickly patch the vulnerability that allowed the unauthorized access without isolating the server, assuming this will stop further exfiltration.
Initiate a full system restore from the most recent backup to overwrite any compromised data, without a full forensic investigation.
Immediately notify all potentially affected customers and regulatory bodies before taking any containment or investigative steps.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free