CompTIA Security+ Certification SY0-601: The Total Course - Chapter 13 Exam Question Review

CompTIA Security+ Certification SY0-601: The Total Course - Chapter 13 Exam Question Review

Assessment

Interactive Video

Information Technology (IT), Architecture

University

Hard

Created by

Quizizz Content

FREE Resource

The video tutorial discusses an intrusion detection alarm that alerts suspicious activity on a user workstation. The immediate response is to disable the network switch port connected to the workstation. This action is defined as 'containment,' which prevents the device from communicating on the network. The tutorial clarifies that containment is not recovery, prevention, or detection, but a temporary measure to control the incident.

Read more

5 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is the first step taken when an intrusion detection alarm alerts you to suspicious activity?

Run a virus scan

Notify the user

Reboot the workstation

Disable the network switch port

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which term best describes the action of disabling the network switch port?

Recovery

Detection

Prevention

Containment

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Why is the action of disabling the network switch port not considered recovery?

Because it involves fixing the problem

Because it only temporarily stops the issue

Because it detects the issue

Because it prevents future incidents

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What role does the intrusion detection system play in this scenario?

It contains the incident

It prevents the incident

It detects the suspicious activity

It recovers the system

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which of the following is not a correct description of the action taken?

Prevention

Containment

Recovery

Detection