Quiz 11 Question 5 of 20

A SOC analyst has confirmed a malware infection, isolated the affected server, and blocked command-and-control traffic. The containment step is complete, and no evidence preservation issues remain. What should happen next in the incident response process?

Select an answer to reveal the explanation.

Motivation