Verified Q&A Bank

Free Practice Question #16418

In a AWS account involving the branch-office firewall and audit logs, A workstation launches encoded PowerShell and attempts credential dumping. What should EDR do first under a containment playbook?

+1-0
MCQ
A
Isolate the endpoint and alert analysts
B
Approve the process permanently
C
Increase mailbox quota
D
Disable TLS globally
CompTIA-SecurityPlusSY0-701practice-test-05domain-4-security-operations4.1-secure-resourcesedr-containmentdifficulty-3

Want to try a full mock exam?

Unlock the full timed mock test series for CompTIA-SecurityPlus to see detailed analytics and compete on the leaderboard.

Start Full Test Series
In a AWS account involving the branch-office firewall and au... - Free Practice Question | FreeTestSeries