Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam CAS-004 All Questions
Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

CompTIA CASP CAS-004 Question # 69 Topic 8 Discussion

CAS-004 Exam Topic 8 Question 69 Discussion:
Question #: 69
Topic #: 8

A SOC analyst received an alert about a potential compromise and is reviewing the following SIEM logs:

CAS-004 Question 69

Which of the following is the most appropriate action for the SOC analyst to recommend?


A.

Disabling account JDoe to prevent further lateral movement


B.

Isolating laptop314 from the network


C.

Alerting JDoe about the potential account compromise


D.

Creating HIPS and NIPS rules to prevent logins


Get Premium CAS-004 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.