QuestionQ3
Incident Response ProcessesAn incident response team recommends changes after reviewing a recent compromise in which:
- A large number of events and logs were involved.
- Team members could not identify anomalous behavior and escalate it promptly.
- Several network systems were affected because detection was delayed.
- Security engineers mitigated the threat and restored systems to a stable state.
- The issue recurred shortly afterward and systems became unstable again because the correct information was not collected during the initial identification phase.
Which two recommendations should be made to improve the incident response process?
Choose two
- A Formalize reporting requirements and responsibilities to update management and internal stakeholders throughout the incident-handling process effectively.
- B Improve the mitigation phase to ensure causes can be quickly identified, and systems returned to a functioning state.
- C Implement an automated operation to pull systems events/logs and bring them into an organizational context.
- D Allocate additional resources for the containment phase to stabilize systems in a timely manner and reduce an attack's breadth.
- E Modify the incident handling playbook and checklist to ensure alignment and agreement on roles, responsibilities, and steps before an incident occurs.
Community Discussion