A cyber-incident response analyst is investigating a suspected cryptocurrency miner on a company's server. Which of the following is the FIRST step the analyst should take?
A) Create a full disk image of the server's hard drive to look for the file containing the malware.
B) Run a manual antivirus scan on the machine to look for known malicious software.
C) Take a memory snapshot of the machine to capture volatile information stored in memory.
D) Start packet capturing to look for traffic that could be indicative of command and control from the miner.
Correct Answer:
Verified
Q145: A security is responding to an incident
Q146: Massivelog.log has grown to 40GB on a
Q147: Which of the following are components of
Q148: A security analyst is investigating a system
Q149: Which of the following session management techniques
Q151: An organization was alerted to a possible
Q152: A security analyst is evaluating two vulnerability
Q153: Which of the following secure coding techniques
Q154: A company is moving from the use
Q155: The help desk provided a security analyst
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents