QuestionQ3

Incident Response Processes

An incident response team recommends changes after reviewing a recent compromise in which:

  • A large number of events and logs were involved.
  • Team members could not identify anomalous behavior and escalate it promptly.
  • Several network systems were affected because detection was delayed.
  • Security engineers mitigated the threat and restored systems to a stable state.
  • The issue recurred shortly afterward and systems became unstable again because the correct information was not collected during the initial identification phase.

Which two recommendations should be made to improve the incident response process?

Choose two
Explanation

Automated collection and contextualization of system events and logs helps analysts detect anomalous behavior promptly amid high event volumes. A revised incident-handling playbook and checklist establishes agreed roles, responsibilities, and identification steps before an incident, helping ensure the necessary information is gathered and reducing the risk of recurrence.

Community Discussion

No comments yet. Be the first to start the discussion!