QuestionQ6
Incident Response Concepts and ApplicationAn incident response team is addressing a worm infection among its user workstations. The team created an IPS signature to detect and block worm activity on the border IPS, and then removed the worm artifacts or the workstations triggering the rule. Despite these actions, worm activity continued for days afterward. Where did the incident response team fail?
- A The team did not adequately apply lessons learned from the incident
- B The custom rule did not detect all infected workstations
- C They did not receive timely notification of the security event
- D The team did not understand the worm’s propagation method
Community Discussion