CCSA Exam QuestionsBrowse all questions from this exam

CCSA Exam - Question 169


You have discovered suspicious activity in your network. What is the BEST immediate action to take?

Show Answer
Correct Answer:

Discussion

2 comments
Sign in to comment
Mrnemesis79Option: C
Nov 24, 2024

C is correct

keikei1228Option: C
Nov 25, 2024

The best immediate action to take is C. Create a Suspicious Activity Monitoring (SAM) rule to block that traffic. Creating a SAM rule allows you to quickly block the suspicious activity without needing to install a new policy, which can be time-consuming. SAM rules are designed for immediate response to suspicious activities and can be enforced quickly to mitigate potential threats.