CompTIA CySA+ (CS0-002) — Question 8

A team of security analysts has been alerted to potential malware activity. The initial examination indicates one of the affected workstations is beaconing on TCP port 80 to five IP addresses and attempting to spread across the network over port 445. Which of the following should be the team's NEXT step during the detection phase of this response process?

Answer options

Correct answer: D

Explanation

The correct answer is D, as identifying potentially affected systems is crucial for understanding the scope of the incident and mitigating the threat. While options A and B involve communication and immediate containment, they do not directly contribute to the detection phase, and option C, while proactive, does not focus on identifying other affected systems.