Free CompTIA CySA+ CS0-003 Practice Question

A cybersecurity analyst has identified an ongoing attack on a virtualized server environment. While the analyst has implemented network segmentation, they must now decide the most effective isolation step to preserve evidence and maintain operations. The environment includes a mix of live client services and development systems. Which of the following actions should the analyst take FIRST?

  • Reconfigure the virtual network interfaces to an isolated VLAN

  • Suspend the affected virtual machines, preserving their operation states

  • Immediately perform forensic imaging of the affected virtual machines

  • Update firewall rules to restrict traffic to and from the virtual machines' current IP addresses

This question's topic:
CompTIA CySA+ CS0-003 / 
Incident Response and Management
Your Score:

Check or uncheck an objective to set which questions you will receive.