300-215 CBRFIR: Conducting Forensic Analysis and Incident Response Using Cisco Technologies for Cybersecurity
By Cisco · Question Mode
QuestionQ3
Incident Response Processes
An incident response team recommends changes after reviewing a recent compromise in which:
A large number of events and logs were involved.
Team members could not identify anomalous behavior and escalate it promptly.
Several network systems were affected because detection was delayed.
Security engineers mitigated the threat and restored systems to a stable state.
The issue recurred shortly afterward and systems became unstable again because the correct information was not collected during the initial identification phase.
Which two recommendations should be made to improve the incident response process?
Choose two
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion