- Get link
- X
- Other Apps
CYB 205 Infrastructure Administration
Q: Alejandro is an incident response analyst for a large corporation. He is on the midnight shift when an intrusion detection system alerts him to a potential brute-force password attack against one of the company’s critical information systems. He performs an initial triage of the event before taking any additional action.
A: Activate the incident response team.
Explanation: The incident response process consists of a series of steps that start with detection and run through response, mitigation, reporting, recovery, and remediation, ending with a lessons learned and onward preparation phase. After the detection of a security incident, the next step in the process is the response, which should follow the organization’s formal incident response procedure. The first step of this procedure is activating the appropriate teams, including the organization's computer security incident response team (CSIRT).Answers A and D are incorrect. Lessons learned involves getting to the root of how and why the incident happened, evaluating how well your incident response plan worked to resolve the issue, and identifying improvements that need to be made.Answer B is incorrect. The preparation phase involves implementing the right tools and setting up the right processes ahead of an incident occurring.
- Get link
- X
- Other Apps
Comments
Post a Comment