QuestionQ66
Incident responseYou received a Container Threat Detection alert that an added binary was executed in a business-critical workload. You must investigate and respond to this incident. What should you do?
Choose two
- A Notify the workload owner. Follow the response playbook, and ask the threat hunting team to identify the root cause of the incident.
- B Review the finding, investigate the pod and related resources, and research the related attack and response methods.
- C Review the finding, quarantine the cluster containing the running pod, and delete the running pod to prevent further compromise.
- D Silence the alert in the Security Command Center (SCC) console, as the alert is a low severity finding.
- E Keep the cluster and pod running, and investigate the behavior to determine whether the activity is malicious.
Community Discussion