CompTIA CySA+ CS0-003 Practice Question
Your team has identified a breach in progress on an endpoint device within the company's network. What is the FIRST step you should take to isolate this device while minimizing the potential for disruption to your organization's operations?
Power off the device to prevent data loss
Disconnect the device from the network
Enable the firewall on the device immediately
Physically remove the device from the office