Exam 312-49v11 Topic 5 Question 968 Discussion

Actual exam question for EC-COUNCIL's 312-49v11 exam
Question #: 968
Topic #: 5
During an investigation, a forensics analyst discovers an unusual increase in outbound network traffic, network traffic traversing on non-standard ports, and multiple failed login attempts on a host system. The analyst also found that certain programs were using these unusual ports, appearing to be legitimate. If these are the primary Indicators of Compromise, what should be the next immediate step in the investigation to contain the intrusion effectively?

Suggested Answer: A Vote an answer

by priyankaverma1927 at Jun 20, 2025, 01:36 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
priyankaverma1927
2025-06-20 01:36:47
Selected Answer: B
B. Enforce stringent password policies and re-authenticate all users
Helps neutralize compromised accounts

Forces re-login, potentially locking out unauthorized sessions

Prevents continued misuse of stolen credentials

Helps restore trust in the identity and access control system

A. Examining logs for repeated file requests
🔄 Useful for post-incident analysis, but not an immediate containment measure.
upvoted 1 times
...
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10