nerdexam
Cisco

300-215 · Question #107

An incident response team is recommending changes after analyzing a recent compromise in which: - a large number of events and logs were involved; - team members were not able to identify the anomalou

Sign in or unlock 300-215 to reveal the answer and full explanation for question #107. The question stem and answer options stay visible for context.

Submitted by layla.eg· Mar 6, 2026Incident Response Processes

Question

An incident response team is recommending changes after analyzing a recent compromise in which:

  • a large number of events and logs were involved;
  • team members were not able to identify the anomalous behavior and escalate it in a timely

manner;

  • several network systems were affected as a result of the latency in detection;
  • security engineers were able to mitigate the threat and bring systems back to a stable state; and
  • the issue reoccurred shortly after and systems became unstable again because the correct

information was not gathered during the initial identification phase. Which two recommendations should be made for improving the incident response process? (Choose two.)

Options

  • AFormalize reporting requirements and responsibilities to update management and internal
  • BImprove the mitigation phase to ensure causes can be quickly identified, and systems returned to
  • CImplement an automated operation to pull systems events/logs and bring them into an
  • DAllocate additional resources for the containment phase to stabilize systems in a timely manner
  • EModify the incident handling playbook and checklist to ensure alignment and agreement on roles,

Unlock 300-215 to see the answer

You've previewed enough free 300-215 questions. Unlock 300-215 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#incident response process#post-incident review#playbook improvement#log management
Full 300-215 Practice