Question 1 of 29
Upon reviewing a critical security alert indicating a potential malware infection on several user workstations, the IT security team is under immense pressure from management to restore full operational capacity as quickly as possible. The security analyst is tasked with resolving the issue, but the urgency of the business demands is clashing with the need for a thorough and secure remediation process. What is the most appropriate course of action for the security analyst to take?
Immediately isolate the affected workstations from the network to prevent further spread, conduct a detailed forensic analysis to identify the threat and its impact, and then proceed with remediation and secure reintegration of the systems.
Apply a quick patch or remove the suspected malware from the affected machines and bring them back online immediately to meet the business's urgent demand for service restoration.
Restore the affected workstations from the most recent system backups without further investigation, assuming the backups are clean and will resolve the issue.
Temporarily disable the endpoint security solutions on the affected machines to allow for faster manual intervention and quicker resolution of the suspected malware.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free