300-215 CBRFIR: Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity
By Cisco · Question Mode
QuestionQ22
Incident Response Processes
A security team is reviewing lessons learned and proposing process changes after a security-breach incident. During the incident, security-team members did not report abnormal system activity because of a heavy project workload. In addition, once the incident was identified, the response required six hours because management was unavailable to provide the necessary approvals. Which two actions will prevent these problems from occurring in the future?
Choose two
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion