Which of the following is the NEXT step the team should take?

Last Updated on August 15, 2021 by Admin 3

A computer emergency response team is called at midnight to investigate a case in which a mail server was restarted. After an initial investigation, it was discovered that email is being exfiltrated through an active connection.

Which of the following is the NEXT step the team should take?

  • Identify the source of the active connection
  • Perform eradication of active connection and recover
  • Performance containment procedure by disconnecting the server
  • Format the server and restore its initial configuration
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments