QuestionQ84

Incident and Risk Management

A global financial institution suffered a sophisticated cyberattack in which attackers accessed the internal network and exfiltrated sensitive data over several months. The attack was complex, involving a combination of phishing, malware, and exploitation of system vulnerabilities. After discovering the attack, the institution began its incident-response process. Given the nature and severity of the incident, what should be the primary focus of the incident response team’s initial efforts?

  • A Implementing a communication plan to manage public relations and customer communication regarding the breach
  • B Isolating affected systems to prevent further data exfiltration and analyzing network traffic for anomalies
  • C Notifying law enforcement and regulatory bodies immediately to comply with legal and regulatory requirements
  • D Conducting a comprehensive system audit to identify all vulnerabilities and patch them immediately
Explanation

The initial priority in an active, severe breach is containment: isolate affected systems to halt further unauthorized access and data exfiltration, while analyzing network traffic to identify malicious activity and determine the incident’s scope. Public communications, regulatory notifications, vulnerability remediation, and comprehensive audits should follow as appropriate once the immediate threat is controlled.

Community Discussion

No comments yet. Be the first to start the discussion!