QuestionQ321

Incident Management

An information security manager has received notification of a compromised endpoint device. Which of the following is the BEST action to prevent additional damage?

  • A Run a virus scan on the endpoint device
  • B Wipe and reset the endpoint device
  • C Power off the endpoint device
  • D Isolate the endpoint device
Explanation

Isolating a compromised endpoint immediately contains the incident by blocking its network communications, limiting further spread, unauthorized access, and potential data loss while preserving the system for investigation.

Community Discussion

No comments yet. Be the first to start the discussion!