Question 1 of 30
The monitoring system demonstrates unusual outbound network traffic patterns originating from a server containing customer billing information. This activity is flagged as a potential security incident. As the security analyst, what is the most appropriate immediate course of action to investigate this anomaly while adhering to data privacy regulations?
Initiate a focused review of network logs and system activity specifically related to the server exhibiting the anomalous traffic, prioritizing the identification of the nature and destination of the outbound data.
Immediately copy all server logs and user activity data from all systems across the entire network to an isolated forensic environment for comprehensive analysis.
Issue an immediate company-wide alert to all employees and customers regarding a potential data breach, advising them to change passwords.
Temporarily disable all external network access for all employees until the investigation is fully completed to prevent further data exfiltration.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free