QuestionQ116
Incident Response ProcessesDuring an overnight shift, a cybersecurity team at a global trading firm identifies irregular activity. The network intrusion system flags a spike in encrypted traffic from high-value transaction servers to an anonymous Tor exit node. At the same time, internal surveillance tools report unusual database queries and access patterns that resemble exfiltration techniques. Which focused action should the team take first to analyze and address these possible security threats?
- A Implement dynamic firewall rules to block suspicious outbound connections.
- B Engage advanced decryption and anomaly analysis for the flagged traffic.
- C Cross-reference database access logs with user activity profiles.
- D Initiate immediate containment protocols for transaction servers.
Community Discussion