Question: A computer emergency response team is called at midnight to investigate a case in which a mail server was restarted. After an initial investigation, it

A computer emergency response team is called at midnight to investigate a case in which a mail server was restarted. After an initial investigation, it was discovered that email is being exfiltrated through an active connection. Which of the following is the NEXT step the team should take?

  • Identify the source of the active connection

  • Perform eradication of the active connection and recover

  • Perform a containment procedure by disconnecting the server

  • Format the server and restore its initial configuration

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!