QuestionQ2
Incident Response ProcessesAn employee receives an email from a "trusted" person that contains a hyperlink involving malvertising. The employee clicks the link, and malware is downloaded. An information analyst notices an alert in the SIEM and engages the cybersecurity team to analyze the incident according to the incident response plan. Which event detail should be included in this root cause analysis?
- A phishing email sent to the victim
- B alarm raised by the SIEM
- C information from the email header
- D alert identified by the cybersecurity team
Community Discussion