nerdexam
Cisco

350-201 · Question #45

The physical security department received a report that an unauthorized person followed an authorized individual to enter a secured premise. The incident was documented and given to a security…

The correct answer is D. Identify movement of the attacker in the enterprise. After a tailgating incident is documented, the security specialist must first trace the unauthorized individual's path through the facility to establish the scope of potential exposure before any further action.

Processes

Question

The physical security department received a report that an unauthorized person followed an authorized individual to enter a secured premise. The incident was documented and given to a security specialist to analyze. Which step should be taken at this stage?

Options

  • ADetermine the assets to which the attacker has access
  • BIdentify assets the attacker handled or acquired
  • CChange access controls to high risk assets in the enterprise
  • DIdentify movement of the attacker in the enterprise

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    16% (5)
  • D
    72% (23)

Why each option

After a tailgating incident is documented, the security specialist must first trace the unauthorized individual's path through the facility to establish the scope of potential exposure before any further action.

ADetermine the assets to which the attacker has access

Determining which assets the attacker can access is a downstream step that requires first knowing where in the facility the attacker traveled.

BIdentify assets the attacker handled or acquired

Identifying specific assets handled or acquired is only possible after the attacker's movement and locations visited have been established.

CChange access controls to high risk assets in the enterprise

Changing access controls is a remediation action taken after analysis is complete, not during the initial investigative stage.

DIdentify movement of the attacker in the enterpriseCorrect

Identifying the attacker's movement within the enterprise is the foundational analysis step because it establishes which areas, systems, and assets were potentially accessed during the intrusion. Without mapping the physical and logical path of the attacker, investigators cannot accurately determine what was touched, viewed, or compromised. All subsequent containment and remediation decisions depend on this movement analysis.

Concept tested: Physical security tailgating incident analysis steps

Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final

Topics

#physical security#tailgating#attacker movement#incident analysis

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice