312-50V9 · Question #141
The intrusion detection system at a software development company suddenly generates multiple alerts regarding attacks against the company's external webserver, VPN concentrator, and DNS servers…
The correct answer is C. Investigate based on the potential effect of the incident. When multiple security alerts fire simultaneously, triage by potential impact ensures the most critical systems and data receive attention first.
Question
The intrusion detection system at a software development company suddenly generates multiple alerts regarding attacks against the company's external webserver, VPN concentrator, and DNS servers. What should the security team do to determine which alerts to check first?
Options
- AInvestigate based on the maintenance schedule of the affected systems.
- BInvestigate based on the service level agreements of the systems.
- CInvestigate based on the potential effect of the incident.
- DInvestigate based on the order that the alerts arrived in.
How the community answered
(50 responses)- A14% (7)
- B6% (3)
- C76% (38)
- D4% (2)
Why each option
When multiple security alerts fire simultaneously, triage by potential impact ensures the most critical systems and data receive attention first.
Maintenance schedules reflect planned downtime windows and have no bearing on the urgency or severity of an active security incident.
Service level agreements define uptime and performance commitments but do not measure the security impact or threat severity of an ongoing attack.
Investigating based on potential effect follows the risk-based incident response model recommended by NIST SP 800-61, where incidents are triaged by their possible business impact, data sensitivity, and criticality of the affected system. This ensures that incidents with the highest potential for harm - such as data exfiltration or service disruption affecting customers - are addressed before lower-severity events. The other prioritization methods (order, maintenance schedule, SLA) do not measure security risk or severity.
Alert arrival order is arbitrary and does not reflect the actual risk, severity, or potential damage of the underlying security events.
Concept tested: Incident response triage and prioritization by impact
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.