Which of the following should the administrator do NEXT according to the incident response process?

A systems administrator has isolated an infected system from the network and terminated the malicious process from executing.
Which of the following should the administrator do NEXT according to the incident response process?
A. Restore lost data from a backup.
B. Wipe the system.
C. Document the lessons learned.
D. Determine the scope of impact.

How To Pass SY0-601 Exam?

CompTIA SY0-601 PDF dumps.

High quality SY0-601 pdf and software. VALID exam to help you pass.

comptia-exams

4 thoughts on “Which of the following should the administrator do NEXT according to the incident response process?

  1. Admin has isolated an infected system from the network AND TERMINATED the malicious process (implying that it has been removed) If it has been removed, then yes restore lost data, so A. thanks for your deception comptia.

  2. I am leaning toward D. Given the information in the question, I think we are still in identification. Definitely not A or C.

  3. My guess is D. Seem like we’re still at the identification part of the response. A would be be apart of recovery.

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.