Câu 4: GCED: GIAC Certified Enterprise Defender
An incident response team is handling a worm infection among their user workstations. They created an IPS signature to detect and block worm activity on the border IPS, then removed the worms artifacts or workstations triggering the rule. Despite this action, worm activity continued for days after. Where did the incid…
Nội dung câu hỏi
An incident response team is handling a worm infection among their user workstations. They created an IPS signature to detect and block worm activity on the border IPS, then removed the worms artifacts or workstations triggering the rule. Despite this action, worm activity continued for days after. Where did the incident response team fail?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. The team did not adequately apply lessons learned from the incident
- B. The custom rule did not detect all infected workstations — đáp án hiện tại
- C. They did not receive timely notification of the security event
- D. The team did not understand the worm’s propagation method
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.