QuestionQ93

Incident Response

Sarah Chen is a Security Analyst at Midwest Financial, a regional bank headquartered in Chicago. At 2 AM, her SOC team identifies unusual data-exfiltration patterns and signs of lateral movement across multiple servers that contain sensitive customer data. The activity seems sophisticated and may require forensic analysis and system restoration. Which team should have primary responsibility for managing this complex security incident?

  • A Threat Intelligence Team
  • B SOC (Security Operations Center) Team
  • C Security Engineering Team
  • D IRT (Incident Response Team)
Explanation

An Incident Response Team leads complex security incidents by coordinating containment, forensic investigation, eradication, recovery, and restoration. A SOC typically detects, monitors, and triages suspicious activity, while the Incident Response Team manages the full response to a significant compromise.

Community Discussion

No comments yet. Be the first to start the discussion!