350-201 · Question #135
Engineers are working to document, list, and discover all used applications within an organization. During the regular assessment of applications from the HR backup server, an engineer discovered an…
The correct answer is A. Determine the type of data stored on the affected asset, document the access logs, and engage D. Initiate a triage meeting with department leads to determine if the application is owned internally. When an unknown, ownerless application is found communicating externally over unencrypted channels, the immediate next steps are to assess data exposure risk and escalate to leadership to confirm ownership before any remediation.
Question
Engineers are working to document, list, and discover all used applications within an organization. During the regular assessment of applications from the HR backup server, an engineer discovered an unknown application. The analysis showed that the application is communicating with external addresses on a non- secure, unencrypted channel. Information gathering revealed that the unknown application does not have an owner and is not being used by a business unit. What are the next two steps the engineers should take in this investigation? (Choose two.)
Options
- ADetermine the type of data stored on the affected asset, document the access logs, and engage
- BIdentify who installed the application by reviewing the logs and gather a user access log from the
- CVerify user credentials on the affected asset, modify passwords, and confirm available patches
- DInitiate a triage meeting with department leads to determine if the application is owned internally
How the community answered
(16 responses)- A81% (13)
- B6% (1)
- C13% (2)
Why each option
When an unknown, ownerless application is found communicating externally over unencrypted channels, the immediate next steps are to assess data exposure risk and escalate to leadership to confirm ownership before any remediation.
Determining the type of data stored on the affected asset establishes the potential breach impact, particularly given the unencrypted external communication. Documenting access logs preserves forensic evidence needed to understand the scope and timeline of the exposure.
Reviewing installation logs to identify who installed the application is a valid forensic step but is secondary - data risk and organizational ownership must be assessed before diving into log attribution.
Verifying credentials, modifying passwords, and patching are remediation actions that are premature at this stage; the investigation must first characterize the threat and confirm ownership before applying fixes.
Initiating a triage meeting with department leads is the appropriate escalation step to determine if any business unit has undocumented ownership of the application before taking disruptive action. This prevents prematurely removing a tool that may have a legitimate but undocumented purpose.
Concept tested: Incident response steps for unknown rogue application discovery
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.