QuestionQ67
Incident Response and ManagementAn analyst is preparing an after-action report following an incident in which multiple systems were compromised over the course of several days. The report includes raw event logs collected from each of the compromised systems, and the analyst determines that a patient-zero system cannot be identified. Which of the following should the analyst do to determine the patient-zero system?
- A Establish an accurate timeline of events.
- B Enable monitoring on the compromised systems.
- C Isolate the compromised systems before remediation.
- D Improve the content for incident updates during shift handoff.
- E Perform a reverse composition analysis on malware packages.
Community Discussion