350-201(NEW-127Q) · Question #67
An EDR system alerted the incident response team about the activity of malicious files on the HR manager endpoint. The infected endpoint was isolated from the network. Further examination of the…
The correct answer is D. Investigate other employees' endpoints and quarantine infected ones. Option D is correct because the scenario is still in the Containment phase of NIST 800-61's cycle (Preparation → Detection & Analysis → Containment, Eradication & Recovery → Post-Incident Activity). The HR endpoint was isolated (short-term containment), but since phishing…
Question
Options
- AAnalyze the attack vector and prepare the incident report for management.
- BSend warning emails to vulnerable employees.
- CEradicate the malicious file from infected endpoints of HR managers.
- DInvestigate other employees' endpoints and quarantine infected ones.
How the community answered
(23 responses)- A9% (2)
- B13% (3)
- C4% (1)
- D74% (17)
Explanation
Option D is correct because the scenario is still in the Containment phase of NIST 800-61's cycle (Preparation → Detection & Analysis → Containment, Eradication & Recovery → Post-Incident Activity). The HR endpoint was isolated (short-term containment), but since phishing emails targeted multiple employees, the team must determine the full scope of infection by investigating other endpoints and quarantining any compromised ones before moving forward - otherwise eradication would be incomplete.
Why the distractors are wrong:
- A is wrong because incident reporting for management is a Post-Incident Activity step, not something done while the threat is still active and unscoped.
- B is wrong because warning emails, while useful, are not the prioritized next step in the NIST workflow - you must finish containing the threat before shifting to awareness messaging.
- C is wrong because eradication comes after full containment; cleaning only the HR manager's machine while other infected endpoints remain active would leave the incident unresolved.
Memory tip: Think of NIST 800-61 containment as "catch them all before you clean" - you must identify and quarantine every infected system before eradicating anything, especially when a phishing campaign implies multiple potential victims.
Topics
Community Discussion
No community discussion yet for this question.