Exam 312-49v11 Topic 5 Question 968 Discussion
Actual exam question for EC-COUNCIL's 312-49v11 exam
Question #: 968
Topic #: 5
Question #: 968
Topic #: 5
During an investigation, a forensics analyst discovers an unusual increase in outbound network traffic, network traffic traversing on non-standard ports, and multiple failed login attempts on a host system. The analyst also found that certain programs were using these unusual ports, appearing to be legitimate. If these are the primary Indicators of Compromise, what should be the next immediate step in the investigation to contain the intrusion effectively?
Suggested Answer: A Vote an answer
by priyankaverma1927 at Jun 20, 2025, 01:36 AM
0
0
0
10
Comments
priyankaverma1927
2025-06-20 01:36:47Helps neutralize compromised accounts
Forces re-login, potentially locking out unauthorized sessions
Prevents continued misuse of stolen credentials
Helps restore trust in the identity and access control system
A. Examining logs for repeated file requests
🔄 Useful for post-incident analysis, but not an immediate containment measure.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).