Question 1 of 30
Governance review demonstrates that a critical server has been compromised by advanced persistent threats (APTs). The incident response team is under immense pressure to restore services to minimize business disruption. What is the most appropriate initial action to ensure the integrity of digital evidence while initiating containment?
Immediately create forensically sound images of the affected server's storage media before any remediation or analysis is performed.
Proceed with immediate malware removal and system cleanup to restore normal operations as quickly as possible.
Conduct a rapid scan for malware and then begin system restoration, documenting only the malware found.
Collect relevant logs and configuration files from the server, and then proceed with restoration.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free