QuestionQ4

Security Policies and Procedures

The SOC team has verified a potential indicator of compromise on an endpoint. The team has narrowed the executable file type down to a new trojan family.

According to the NIST Computer Security Incident Handling Guide, what is the next step for handling this event?

Explanation

NIST SP 800-61 Rev. 2 includes researching suspected malicious activity—such as consulting search engines and knowledge bases—during detection and analysis. Public information about the newly identified trojan family can establish its behavior and help determine the incident before prioritization or containment.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!