QuestionQ2

Incident Response Processes

An employee receives an email from a "trusted" person that contains a hyperlink involving malvertising. The employee clicks the link, and malware is downloaded. An information analyst notices an alert in the SIEM and engages the cybersecurity team to analyze the incident according to the incident response plan. Which event detail should be included in this root cause analysis?

  • A phishing email sent to the victim
  • B alarm raised by the SIEM
  • C information from the email header
  • D alert identified by the cybersecurity team
Explanation

A root cause analysis records the initiating event that enabled the incident. The phishing email containing the malicious hyperlink led to the employee’s click and subsequent malware download; SIEM alarms and team alerts are detection events rather than the underlying cause.

Community Discussion

No comments yet. Be the first to start the discussion!