CompTIA Security+ SY0-601 – Question053

A security analyst has identified malware spreading through the corporate network and has activated the
CSIRT. Which of the following should the analyst do NEXT?


A.
Review how the malware was introduced to the network.
B. Attempt to quarantine all infected hosts to limit further spread.
C. Create help desk tickets to get infected systems reimaged.
D. Update all endpoint antivirus solutions with the latest updates.

Correct Answer: B