Valid CAS-005 Dumps shared by ExamDiscuss.com for Helping Passing CAS-005 Exam! ExamDiscuss.com now offer the newest CAS-005 exam dumps, the ExamDiscuss.com CAS-005 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com CAS-005 dumps with Test Engine here:
A security analyst notices a number of SIEM events that show the following activity: 10/30/2020 - 8:01 UTC - 192.168.1.1 - sc stop HinDctend 10/30/2020 - 8:05 UTC - 192.168.1.2 - c:\program files\games\comptidcasp.exe 10/30/2020 - 8:07 UTC - 192.168.1.1 - c:\windows\system32\cmd.exe /c powershell 10/30/2020 - 8:07 UTC - 192.168.1.1 - powershell -> 40.90.23.154:443 Which of the following response actions should the analyst take first?
Correct Answer: C
The first immediate action in an active incident iscontainment.Blocking the IP address (40.90.23.154)at the network edge prevents further communication with the malicious external server. Disabling PowerShell or removing local admin privileges are valid hardening steps, but containment by network control is the highest priority during an active compromise to stop data exfiltration or further command and control activity. Reference:CompTIA SecurityX CAS-005, Domain 2.0: Apply incident response techniques focusing on immediate containment actions.