An administrator discovers unauthorized software installed on a Windows Server 2012 R2 production server. According to incident response best practices, what should be done FIRST?
-
A
Immediately reformat the server to eliminate the threat
-
B
Document the discovery, isolate the server, and follow the incident response plan
-
C
Send an email to all users warning them of the breach
-
D
Delete the unauthorized software and resume normal operations without reporting