350-201(NEW-127Q) · Question #76
An organization detected unauthorized access to its customer database that contains sensitive PII. The incident response team must respond swiftly using automation and escalation protocols to…
The correct answer is C. Leverage automated playbooks to trigger network segmentation, relevant machine isolation, and automatically gather forensic details from potentially compromised hosts. Option C is correct because it aligns with modern incident response best practices: automation + speed + scoped containment. Automated playbooks enable immediate network segmentation and host isolation without human delay, while simultaneously gathering forensic evidence…
Question
Options
- ADeploy additional IDS, manually inspect system logs for anomalies, escalate to external incident response consultants, and apply forensics tools to identify data exfiltration.
- BManually disable third-party integrations, escalate to cloud service providers, initiate full packet capture, and enforce policy-based user account restrictions.
- CLeverage automated playbooks to trigger network segmentation, relevant machine isolation, and automatically gather forensic details from potentially compromised hosts.
- DAutomate full system shutdown, escalate directly to compliance auditors, and enforce organization-wide password resets to prevent further access.
How the community answered
(29 responses)- A3% (1)
- B17% (5)
- C69% (20)
- D10% (3)
Explanation
Option C is correct because it aligns with modern incident response best practices: automation + speed + scoped containment. Automated playbooks enable immediate network segmentation and host isolation without human delay, while simultaneously gathering forensic evidence - satisfying both the containment and investigation phases of the incident response lifecycle in a scalable, repeatable way.
Why the distractors fail:
- A relies heavily on manual log inspection and external consultants, introducing delays that worsen breach impact - the opposite of "swift" response.
- B manually disabling third-party integrations and initiating full packet capture is operationally slow and resource-intensive; it doesn't leverage the automation already available.
- D is too aggressive and indiscriminate - a full system shutdown disrupts business continuity, and escalating directly to compliance auditors skips the technical containment phase entirely; password resets alone don't address an active compromise.
Memory tip: Think "Automate, Isolate, Investigate" - in any incident response question involving automation capabilities, the correct answer will use them to contain first, gather evidence simultaneously, never skip to auditors or shut everything down blindly.
Topics
Community Discussion
No community discussion yet for this question.