QuestionQ6

Incident Response Concepts and Application

An incident response team is addressing a worm infection among its user workstations. The team created an IPS signature to detect and block worm activity on the border IPS, and then removed the worm artifacts or the workstations triggering the rule. Despite these actions, worm activity continued for days afterward. Where did the incident response team fail?

  • A The team did not adequately apply lessons learned from the incident
  • B The custom rule did not detect all infected workstations
  • C They did not receive timely notification of the security event
  • D The team did not understand the worm’s propagation method
Explanation

A border IPS controls traffic at the network perimeter, but it does not necessarily stop a worm from propagating laterally among internal workstations. Effective containment and eradication require understanding the worm’s propagation method so that all transmission paths and infected systems can be identified and addressed.

Community Discussion

No comments yet. Be the first to start the discussion!