A systems administrator has isolated an infected system from the network and terminated the malicious process from executing. Which of the following should the administrator do NEXT according to the incident response process?

🎲 Try a Random Question  |  Total Questions in Quiz: 179  |  🧠 Study this quiz with Flashcards
This question is part of a full practice quiz:
SY0-501 CompTIA Security+ Certification Exam - Practice Test 2 — practice the complete quiz, review flashcards, or try a random question.


A systems administrator has isolated an infected system from the network and terminated the malicious process from executing. Which of the following should the administrator do NEXT according to the incident response process?