nerdexam
EC-Council

212-89 · Question #78

Which stage of the incident response and handling process involves auditing the system and network log files?

The correct answer is B. Incident triage. Auditing the system and network log files is a crucial step in the incident triage phase of the incident response and handling process. During incident triage, incident handlers assess and prioritize incidents based on their severity, impact, and the urgency of the response…

Incident Handling and Response Process

Question

Which stage of the incident response and handling process involves auditing the system and network log files?

Options

  • AContainment
  • BIncident triage
  • CIncident disclosure
  • DIncident eradication

How the community answered

(31 responses)
  • B
    90% (28)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Auditing the system and network log files is a crucial step in the incident triage phase of the incident response and handling process. During incident triage, incident handlers assess and prioritize incidents based on their severity, impact, and the urgency of the response required. Part of this assessment involves reviewing log files to understand the nature of the incident, its scope, and the systems or networks affected. This information helps in categorizing the incident and deciding on the appropriate response actions. Unlike containment, which aims to limit the damage, incident disclosure, which involves communicating about the incident, or incident eradication, which focuses on removing the threat, incident triage is about evaluating and prioritizing the incident based on detailed log analysis among other factors.

Topics

#incident triage#log analysis#incident response phases#network logs

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice