350-201 · Question #45
The physical security department received a report that an unauthorized person followed an authorized individual to enter a secured premise. The incident was documented and given to a security…
The correct answer is D. Identify movement of the attacker in the enterprise. After a tailgating incident is documented, the security specialist must first trace the unauthorized individual's path through the facility to establish the scope of potential exposure before any further action.
Question
The physical security department received a report that an unauthorized person followed an authorized individual to enter a secured premise. The incident was documented and given to a security specialist to analyze. Which step should be taken at this stage?
Options
- ADetermine the assets to which the attacker has access
- BIdentify assets the attacker handled or acquired
- CChange access controls to high risk assets in the enterprise
- DIdentify movement of the attacker in the enterprise
How the community answered
(32 responses)- A3% (1)
- B9% (3)
- C16% (5)
- D72% (23)
Why each option
After a tailgating incident is documented, the security specialist must first trace the unauthorized individual's path through the facility to establish the scope of potential exposure before any further action.
Determining which assets the attacker can access is a downstream step that requires first knowing where in the facility the attacker traveled.
Identifying specific assets handled or acquired is only possible after the attacker's movement and locations visited have been established.
Changing access controls is a remediation action taken after analysis is complete, not during the initial investigative stage.
Identifying the attacker's movement within the enterprise is the foundational analysis step because it establishes which areas, systems, and assets were potentially accessed during the intrusion. Without mapping the physical and logical path of the attacker, investigators cannot accurately determine what was touched, viewed, or compromised. All subsequent containment and remediation decisions depend on this movement analysis.
Concept tested: Physical security tailgating incident analysis steps
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.