CASP+ - CompTIA Advanced Security Practitioner Practice Test
CASP+ - CompTIA Advanced Security Practitioner CASP+ Security Operations and Incident Response
During a security incident, a responder discovers malware on a compromised host.
What is the FIRST action that should be taken according to incident response best practices?
Select your answer
A
Immediately reimage the system
B
Isolate the system from the network while preserving volatile memory
C
Delete all suspicious files
D
Notify law enforcement immediately
Hint