350-201 · Question #19
Employees report computer system crashes within the same week. An analyst is investigating one of the computers that crashed and discovers multiple shortcuts in the system's startup folder. It…
The correct answer is C. Identify affected systems. When multiple systems show signs of the same infection, scoping the incident by identifying all affected systems is the critical next step before performing remediation or deeper forensic investigation.
Question
Employees report computer system crashes within the same week. An analyst is investigating one of the computers that crashed and discovers multiple shortcuts in the system's startup folder. It appears that the shortcuts redirect users to malicious URLs. What is the next step the engineer should take to investigate this case?
Options
- ARemove the shortcut files
- BCheck the audit logs
- CIdentify affected systems
- DInvestigate the malicious URLs
How the community answered
(27 responses)- A7% (2)
- B15% (4)
- C70% (19)
- D7% (2)
Why each option
When multiple systems show signs of the same infection, scoping the incident by identifying all affected systems is the critical next step before performing remediation or deeper forensic investigation.
Removing shortcut files is a remediation action that should occur after the scope of the incident is fully understood, not before other affected systems are identified.
Checking audit logs on a single machine is useful for deeper forensic work but does not address the broader concern that multiple systems may be compromised simultaneously.
Identifying all affected systems determines the full scope and blast radius of the incident. Because multiple employees reported crashes in the same week, the malicious shortcuts likely exist on more than one machine. Scoping the incident first ensures that remediation and investigation efforts address every compromised endpoint, preventing reinfection from untouched systems.
Investigating the malicious URLs is a threat intelligence step that should follow scope identification, as it does not help determine which or how many systems are currently affected.
Concept tested: Incident response scoping and containment prioritization
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.