QuestionQ96

Incident Response Processes

Question Image

Refer to the exhibit. Which two actions should be performed as a result of this information?

Choose two
  • A Block any URLs in received emails.
  • B Blacklist IPs 164.90.168.78 and 199.19.224.83.
  • C Block any access to and from domain apponline-8473.xyz.
  • D Block any malicious activity with xfe-threat-score-10.
  • E Block all emails sent from malicious domain apponline-8473.xyz.
Explanation

The indicator pattern designates the domain apponline-8473.xyz and the IPv4 addresses 164.90.168.78 and 199.19.224.83 as observables associated with phishing activity. Blocking communication with the domain and blacklisting the listed IP addresses applies controls directly to the identified indicators of compromise.

Community Discussion

No comments yet. Be the first to start the discussion!