An incident response team is addressing a worm infection among its user workstations. The team created an IPS signature to detect and block worm activity on the border IPS, and then removed the worm artifacts or the workstations triggering the rule. Despite these actions, worm activity continued for days afterward. Where did the incident response team fail?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion