212-82 · Question #139
A global financial Institution experienced a sophisticated cyber-attack where attackers gained access to the internal network and exfiltrated sensitive data over several months. The attack was…
The correct answer is C. Isolating affected systems to prevent further data exfiltration and analyzing network traffic for. In a sophisticated cyber-attack involving data exfiltration, the primary initial focus for an incident response team is immediate containment to stop ongoing damage and investigate the attack's scope.
Question
A global financial Institution experienced a sophisticated cyber-attack where attackers gained access to the internal network and exfiltrated sensitive data over several months. The attack was complex, involving a mix of phishing, malware, and exploitation of system vulnerabilities. Once discovered, the institution initiated its incident response process. Considering the nature and severity of the incident, what should be the primary focus of the incident response team's initial efforts?
Options
- AImplementing a communication plan to manage public relations and customer communication
- BNotifying law enforcement and regulatory bodies immediately to comply with legal and regulatory
- CIsolating affected systems to prevent further data exfiltration and analyzing network traffic for
- DConducting a comprehensive system audit to identify all vulnerabilities and patch them
How the community answered
(41 responses)- A5% (2)
- B7% (3)
- C68% (28)
- D20% (8)
Why each option
In a sophisticated cyber-attack involving data exfiltration, the primary initial focus for an incident response team is immediate containment to stop ongoing damage and investigate the attack's scope.
Implementing a communication plan is important for stakeholder management but follows initial technical containment and assessment, as accurate information about the breach is required for public relations.
Notifying law enforcement and regulatory bodies is a vital legal and compliance step, but it typically occurs once the incident is contained and its immediate impact is understood, not as the very first technical response.
Isolating affected systems is a critical containment step that immediately prevents further data exfiltration and limits the attacker's reach, while analyzing network traffic helps understand the attack's scope and methods for effective eradication.
Conducting a comprehensive system audit to identify and patch all vulnerabilities is part of the post-incident recovery and improvement phase, not the immediate containment phase when an active attack is still ongoing.
Concept tested: Incident response phases (Containment)
Source: learn.microsoft.com/en-us/security/compass/incident-response-technical-guidance#contain-the-incident
Topics
Community Discussion
No community discussion yet for this question.