9.1.6 PQ NSF
An corporation's pc incident reaction team (CIRT) receives an alert that indicates viable
malicious pastime on a vital server within the community, and that they initiate the CompTIA
incident reaction procedure.
The group follows the incident response lifecycle to deal with the situation, which includes
numerous key steps.
What order must the CIRT comply with whilst acting the CompTIA incident reaction procedure? -
ANS-Detection, analysis, containment, eradication, healing
As a safety analyst, you're looking for a platform to compile all of your protection records
generated by way of unique endpoints.
Which device might you operate? - ANS-SOAR
The laptop incident reaction group (CIRT) has knowledgeable the executives of a massive
monetary institution of unusual network activity, indicating a potential breach.
Which phase of the incident response lifecycle involves investigating the pronounced
uncommon community activity to determine whether or not a genuine protection incident has
befell and assessing the severity of the situation? - ANS-Analysis
The chief of the cybersecurity group for a prime e-commerce employer lately encountered a
chief facts breach that caused the exposure of consumer price information. The group has now
contained the breach and is transferring in the direction of the final section of the incident
reaction cycle. - ANS-Analyze the incident and improve techniques or systems
What is the BEST definition of a safety incident? - ANS-Violation of a protection policy
What is the primary intention of the containment section of cybersecurity incident control
throughout an incident response lifecycle? (Select .) - ANS-Notify stakeholders and identify
other reporting requirements.
Limit the instantaneous impact of the incident even as securing facts and notifying stakeholders.
You have detected and diagnosed a security occasion. What is the first step you should entire? -
ANS-Containment
You need to limit a compromised utility from inflicting harm to other property in your network.
Which strategy have to you appoint? - ANS-Isolation
You want to restrict the impact of a protection breach for a particular record server with sensitive
enterprise information.
An corporation's pc incident reaction team (CIRT) receives an alert that indicates viable
malicious pastime on a vital server within the community, and that they initiate the CompTIA
incident reaction procedure.
The group follows the incident response lifecycle to deal with the situation, which includes
numerous key steps.
What order must the CIRT comply with whilst acting the CompTIA incident reaction procedure? -
ANS-Detection, analysis, containment, eradication, healing
As a safety analyst, you're looking for a platform to compile all of your protection records
generated by way of unique endpoints.
Which device might you operate? - ANS-SOAR
The laptop incident reaction group (CIRT) has knowledgeable the executives of a massive
monetary institution of unusual network activity, indicating a potential breach.
Which phase of the incident response lifecycle involves investigating the pronounced
uncommon community activity to determine whether or not a genuine protection incident has
befell and assessing the severity of the situation? - ANS-Analysis
The chief of the cybersecurity group for a prime e-commerce employer lately encountered a
chief facts breach that caused the exposure of consumer price information. The group has now
contained the breach and is transferring in the direction of the final section of the incident
reaction cycle. - ANS-Analyze the incident and improve techniques or systems
What is the BEST definition of a safety incident? - ANS-Violation of a protection policy
What is the primary intention of the containment section of cybersecurity incident control
throughout an incident response lifecycle? (Select .) - ANS-Notify stakeholders and identify
other reporting requirements.
Limit the instantaneous impact of the incident even as securing facts and notifying stakeholders.
You have detected and diagnosed a security occasion. What is the first step you should entire? -
ANS-Containment
You need to limit a compromised utility from inflicting harm to other property in your network.
Which strategy have to you appoint? - ANS-Isolation
You want to restrict the impact of a protection breach for a particular record server with sensitive
enterprise information.