200-201 · Question #537
A company recently encountered a breach. Critical services went through a disturbance and the integrity of the data was altered. An engineer is investigating the issue and searching through the logs…
The correct answer is C. detection and analysis. Searching SIEM logs to identify what happened and confirm the nature of the breach is part of the detection and analysis phase, where analysts investigate alerts, gather evidence, and validate the
Question
A company recently encountered a breach. Critical services went through a disturbance and the integrity of the data was altered. An engineer is investigating the issue and searching through the logs in the SIEM. Which phase of the incident response is an engineer working on?
Options
- Apost-incident and lessons learned
- Brecovery and restoration
- Cdetection and analysis
- Dcontainment and eradication
How the community answered
(19 responses)- A16% (3)
- B5% (1)
- C74% (14)
- D5% (1)
Explanation
Searching SIEM logs to identify what happened and confirm the nature of the breach is part of the detection and analysis phase, where analysts investigate alerts, gather evidence, and validate the
Topics
Community Discussion
No community discussion yet for this question.