Which actions should you take to stop data leakage and comply with requirements of the company security policy?

The network security team in your company has discovered a threat that leaked partial data on a compromised file server that handles sensitive information. Containment must be initiated and addresses by the CSIRT. Service disruption is not a concern because this server is used only to store files and does not hold any critical workload.

Your company security policy required that all forensic information must be preserved.

Which actions should you take to stop data leakage and comply with requirements of the company security policy?
A . Disconnect the file server from the network to stop data leakage and keep it powered on for further analysis.
B . Shut down the server to stop the data leakage and power it up only for further forensic analysis.
C . Restart the server to purge all malicious connections and keep it powered on for further analysis.
D . Create a firewall rule to block all external connections for this file server and keep it powered on for further analysis.

Answer: C

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments