QuestionQ186

Incident Response

Bonney’s system has been compromised by serious malware.

What primary action is advisable for Bonney to contain the malware incident and prevent it from spreading?

  • A Leave it to the network administrators to handle
  • B Call the legal department in the organization and inform about the incident
  • C Turn off the infected machine
  • D Complaint to police in a formal way regarding the incident
Explanation

Powering off the infected machine immediately halts its activity and network communications, limiting the malware’s ability to propagate to other systems. Administrative, legal, and law-enforcement notification do not themselves contain the active infection.

Community Discussion

No comments yet. Be the first to start the discussion!