QuestionQ598

Incident Management

An organization’s intrusion prevention system (IPS) detected and blocked an unusually high number of external intrusion attempts during a 24-hour period. Which of the following should be the information security manager’s FIRST action?

  • A Perform security assessments on Internet-facing systems.
  • B Identify the source and nature of the attempts.
  • C Review the server and firewall audit logs.
  • D Report the issue to senior management.
Explanation

Initial incident triage should establish the source and nature of the intrusion attempts so the organization can determine their scope, urgency, likely targets, and whether further containment or escalation is needed. Audit-log review may support that investigation, but identifying and characterizing the activity is the primary first action.

Community Discussion

No comments yet. Be the first to start the discussion!