Verified Q&A Bank
Free Practice Question #16418
In a AWS account involving the branch-office firewall and audit logs, A workstation launches encoded PowerShell and attempts credential dumping. What should EDR do first under a containment playbook?
+1-0
MCQA
Isolate the endpoint and alert analystsB
Approve the process permanentlyC
Increase mailbox quotaD
Disable TLS globallyCompTIA-SecurityPlusSY0-701practice-test-05domain-4-security-operations4.1-secure-resourcesedr-containmentdifficulty-3
Want to try a full mock exam?
Unlock the full timed mock test series for CompTIA-SecurityPlus to see detailed analytics and compete on the leaderboard.
Start Full Test Series