nerdexam
EC-Council

212-89 · Question #70

During the vulnerability assessment phase, the incident responders perform various steps as below: 1. Run vulnerability scans using tools 2. Identify and prioritize vulnerabilities 3. Examine and…

The correct answer is C. 4-->1-->2-->3-->6-->5-->7. The correct sequence of steps performed by incident responders during the vulnerability assessment phase is as follows: Perform OSINT information gathering to validate the vulnerabilities (4): Initially, Open Source Intelligence (OSINT) is used to gather information about the…

Incident Handling and Response Process

Question

During the vulnerability assessment phase, the incident responders perform various steps as below: 1. Run vulnerability scans using tools 2. Identify and prioritize vulnerabilities 3. Examine and evaluate physical security 4. Perform OSINT information gathering to validate the vulnerabilities 5. Apply business and technology context to scanner results 6. Check for misconfigurations and human errors 7. Create a vulnerability scan report Identify the correct sequence of vulnerability assessment steps performed by the incident responders.

Options

  • A3-->6-->1-->2-->5-->4-->7
  • B1-->3-->2-->4-->5-->6-->7
  • C4-->1-->2-->3-->6-->5-->7
  • D2-->1-->4-->7-->5-->6-->3

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    7% (3)
  • C
    73% (33)
  • D
    16% (7)

Explanation

The correct sequence of steps performed by incident responders during the vulnerability assessment phase is as follows: Perform OSINT information gathering to validate the vulnerabilities (4): Initially, Open Source Intelligence (OSINT) is used to gather information about the organization's digital footprint and potential vulnerabilities. Run vulnerability scans using tools (1): Next, specialized tools are employed to scan the organization's networks and systems for vulnerabilities. Identify and prioritize vulnerabilities (2): The identified vulnerabilities are then analyzed and prioritized based on their severity and potential impact on the organization. Examine and evaluate physical security (3): Physical security assessments are also crucial as they can impact the overall security posture and protection of digital assets. Check for misconfigurations and human errors (6): This step involves looking for misconfigurations in systems and networks, as well as potential human errors that could lead to vulnerabilities. Apply business and technology context to scanner (5): The results from the scans are evaluated within the context of the business and its technology environment to accurately assess risks. Create a vulnerability scan report (7): Finally, a comprehensive report is created, detailing the vulnerabilities, their severity, and recommended mitigation strategies. This sequence ensures a thorough assessment, prioritizing vulnerabilities that pose the greatest risk and providing actionable insights for mitigation.

Topics

#vulnerability assessment#vulnerability scanning#OSINT#incident response steps

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice