Câu 5: 300-215: Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR)
An incident response team is recommending changes after analyzing a recent compromise in which: ✑ a large number of events and logs were involved; ✑ team members were not able to identify the anomalous behavior and escalate it in a timely manner; ✑ several network systems were affected as a result of the latency in de…
Nội dung câu hỏi
An incident response team is recommending changes after analyzing a recent compromise in which: ✑ a large number of events and logs were involved; ✑ team members were not able to identify the anomalous behavior and escalate it in a timely manner; ✑ several network systems were affected as a result of the latency in detection; ✑ security engineers were able to mitigate the threat and bring systems back to a stable state; and ✑ the issue reoccurred shortly after and systems became unstable again because the correct information was not gathered during the initial identification phase. Which two recommendations should be made for improving the incident response process? (Choose two.)
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Formalize reporting requirements and responsibilities to update management and internal stakeholders throughout the incident-handling process effectively.
- B. Improve the mitigation phase to ensure causes can be quickly identified, and systems returned to a functioning state.
- C. Implement an automated operation to pull systems events/logs and bring them into an organizational context. — đáp án hiện tại
- D. Allocate additional resources for the containment phase to stabilize systems in a timely manner and reduce an attack's breadth.
- E. Modify the incident handling playbook and checklist to ensure alignment and agreement on roles, responsibilities, and steps before an incident occurs. — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.