Question 1 of 30
Process analysis reveals a critical security incident involving potential data exfiltration from several key servers. The incident response team must act quickly to contain the threat and prevent further damage. Given the sensitive nature of the data potentially compromised, which of the following approaches best balances immediate containment with the imperative to preserve evidence for forensic analysis and potential legal proceedings?
Isolate the affected servers from the network, create forensic images of their storage devices, and then proceed with containment and eradication efforts on the isolated systems.
Immediately wipe and re-image all potentially affected servers to ensure no malicious code remains active.
Initiate network segmentation and block all suspicious IP addresses to prevent further communication, then focus on restoring systems from clean backups.
Prioritize restoring affected systems from the most recent clean backups to minimize downtime, and address forensic analysis later.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free