QuestionQ5

Incident Response Processes

A security team identified an above-average number of inbound tcp/135 connection attempts from unidentified senders. The security team is responding according to its incident response playbook. Which two elements are included in the eradication phase for this incident?

Choose two
  • A anti-malware software
  • B data and workload isolation
  • C centralized user management
  • D intrusion prevention system
  • E enterprise block listing solution
Explanation

Eradication eliminates the incident’s underlying cause and removes the attacker’s ability to continue. Centralized user management supports disabling or correcting unauthorized or compromised access, while an intrusion prevention system actively blocks the malicious inbound TCP/135 attempts. Isolation is a containment measure intended to limit spread or impact.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!