Question: A cyber security analyst at a multinational corporation detects abnormal network activities that indicate a possible security breach. The analyst investigates and confirms that an
A cyber security analyst at a multinational corporation detects abnormal network activities that indicate a possible security breach. The analyst investigates and confirms that an unauthorized person has accessed sensitive customer information. The incident response team must act fast to contain the breach and stop further data loss. What should the initial responder do first?
a
Restore affected systems from secure backups to recover and eliminate the threat
b
Disconnect affected server from the network, isolating it from the production environment
c
Notify law enforcement authorities about the incident to initiate immediate action
d
Initiate threat hunting to find evidence of tactics, techniques, and procedures proactively
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
