During an investigation, an analyst discovers the following rule in an executive’s email client:
The executive is not aware of this rule. Which of the following should the analyst do first to evaluate the potential impact of this security incident?
A.
Check the server logs to evaluate which emails were sent to .
B.
Use the SIEM to correlate logging events from the email server and the domain server.
C.
Remove the rule from the email client and change the password.
D.
Recommend that the management team implement SPF and DKIM.
In practice the first thing I did was always option C for this kind of email account being compromised incident. Or I would have been fired when the victim executive realized that those emails he received after I checked his email client were still delivered to the threat actor just because I was busy checking server logs and analyzing potential risk..
ChatGPT:
The first step the analyst should take is option C: Remove the rule from the email client and change the password. This action ensures that the rule no longer affects the executive's emails and prevents further misuse of the email account.
Additionally, the analyst should further investigate the incident, but removing the unauthorized rule is the immediate priority to mitigate any potential impact.
Option A, checking server logs, and Option B, using SIEM to correlate logs, can be part of the broader investigation but aren't the first steps to address the potential security incident. Option D, recommending SPF and DKIM, is related to email security measures but not the immediate response to the incident.
missed that part... Agree A, the answer is in the question.
upvoted 1 times
...
...
This section is not available anymore. Please use the main Exam Page.CS0-002 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
reidsel
Highly Voted 1 year, 11 months agoMeowson
1 year, 11 months agonovolyus
Most Recent 1 year, 5 months agokumax
1 year, 6 months agoTheStudiousPeepz
1 year, 5 months agoSaphi
1 year, 7 months agoDree_Dogg
1 year, 7 months agojohndoe69
1 year, 8 months agoSleezyglizzy
1 year, 9 months agoDutch012
1 year, 10 months agokill_chain
1 year, 9 months ago