After seeing a password-guessing alert in the SIEM, which of the following actions can be used to “contain” the attack? (Choose TWO)

Locking of or resetting user passwords of compromised user accounts

Blocking SSH connections from IP from where the password guessing originated

Blocking outbound port 22 connections from a web server to the Internet (i.e. SRC=Apache Webserver, DST.IP=Any, DST.PORT=22)

Installing file integrity monitoring software on the web server, to detect future tampering of website files

Verified Answer
Correct Option - ab

To get all Infosys Certified Cyber Defender Exam questions Join Group https://bit.ly/infy_premium_group

We're passionate about offering best placement materials and courses!! A one stop place for Placement Materials. We daily post Offcampus updates and Placement Materials.

Qtr No. 213, New Town Yehlanka Indore 454775

admin@prepflix.in