Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

Please provide explanation Please do not copy answers available on the internet, which are often incorrect During an incident, a company's CIRT determines it is

Please provide explanation

Please do not copy answers available on the internet, which are often incorrect

During an incident, a company's CIRT determines it is necessary to observe the continued network-based transactions between a callback domain and the malware running on an enterprise PC. Which of the following techniques would be BEST to enable this activity while reducing the risk of lateral spread and the risk that the adversary would notice any changes?

  • A. Physically move the PC to a separate Internet point of presence.
  • B. Create and apply microsegmentation rules.
  • C. Emulate the malware in a heavily monitored DMZ segment.
  • D. Apply network blacklisting rules for the adversary domain.

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image_2

Step: 3

blur-text-image_3

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Computer Aided Database Design

Authors: Antonio Albano, Valeria De Antonellis, A. Di Leva

1st Edition

0444877355, 978-0444877352

More Books

Students also viewed these Databases questions

Question

3. How has Starbucks changed since its early days?

Answered: 1 week ago