exam questions

Exam SY0-401 All Questions

View all questions & answers for the SY0-401 exam

Exam SY0-401 topic 2 question 98 discussion

Actual exam question from CompTIA's SY0-401
Question #: 98
Topic #: 2
[All SY0-401 Questions]

During which of the following phases of the Incident Response process should a security administrator define and implement general defense against malware?

  • A. Lessons Learned
  • B. Preparation
  • C. Eradication
  • D. Identification
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Incident response procedures involve: Preparation; Incident identification; Escalation and notification; Mitigation steps; Lessons learned; Reporting; Recover/ reconstitution procedures; First responder; Incident isolation (Quarantine; Device removal); Data breach; Damage and loss control. It is important to stop malware before it ever gets hold of a system thus, you should know which malware is out there and take defensive measures - this means preparation to guard against malware infection should be done.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Currently there are no comments in this discussion, be the first to comment!
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...