300-215 · Question #50
A cybersecurity analyst is analyzing a complex set of threat intelligence data from internal and external sources. Among the data, they discover a series of indicators, including patterns of unusual…
The correct answer is B. Propose isolation of affected systems and activating the incident response plan because the. Correlating internal anomalies (unusual traffic, brute‐force logins, file access) with external intelligence of active ransomware campaigns indicates an active compromise, warranting immediate containment and execution of the incident response process.
Question
A cybersecurity analyst is analyzing a complex set of threat intelligence data from internal and external sources. Among the data, they discover a series of indicators, including patterns of unusual network traffic, a sudden increase in failed login attempts, and multiple instances of suspicious file access on the company’s internal servers. Additionally, an external threat feed highlights that threat actors are actively targeting organizations in the same industry using ransomware. Which action should the analyst recommend?
Options
- AAdvise on monitoring the situation passively because network traffic anomalies are coincidental
- BPropose isolation of affected systems and activating the incident response plan because the
- CAdvocate providing additional training on secure login practices because the increase in failed
- DNotify of no requirement for immediate action because the suspicious file access incidents are
How the community answered
(34 responses)- A12% (4)
- B47% (16)
- C32% (11)
- D9% (3)
Explanation
Correlating internal anomalies (unusual traffic, brute‐force logins, file access) with external intelligence of active ransomware campaigns indicates an active compromise, warranting immediate containment and execution of the incident response process.
Topics
Community Discussion
No community discussion yet for this question.