Which of the following is the FIRST step the analyst should take?
A cyber-incident response analyst is investigating a suspected cryptocurrency miner on a company’s server.
Which of the following is the FIRST step the analyst should take?
A . Create a full disk image of the server’s hard drive to look for the file containing the malware.
B . Run a manual antivirus scan on the machine to look for known malicious software.
C . Take a memory snapshot of the machine to capture volatile information stored in memory.
D . Start packet capturing to look for traffic that could be indicative of command and control from the miner.
Answer: D
Latest CS0-002 Dumps Valid Version with 220 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund
                             Subscribe
                            
                        
                                            
                             Login                        
                    
                        0 Comments                    
                                        
                     Inline Feedbacks                    
                    View all comments
                 
	