CompTIA Security+ Exam Prep

Category - Operations

John has detected a breach in security. A hacker is trying to access confidential data from the company’s server. What should be done first?
  1. Detach the server from the network and remove the network cable.
  2. Look for the hacker and penalize him.
  3. Restart the server.
  4. Shut down the server.
Explanation
Answer: A - John should disconnect the network cable to prevent the hacker from gaining further data from the server. It is very important to disconnect/break the path the hacker is using to steal information from. If this is not done instantly, it may lead to a situation where the hacker may steal all data before any action is taken, in spite of the fact that the data theft was discovered.
Was this helpful? Upvote!
Login to contribute your own answer or details

Top questions

Related questions

Most popular on PracticeQuiz