350-201 · Question #51
A payroll administrator noticed unexpected changes within a piece of software and reported the incident to the incident response team. Which actions should be taken at this step in the incident…
The correct answer is B. Determine the damage to the business, extract reports, and save evidence according to a chain. When an incident is first reported, the response team must immediately assess business damage, collect relevant logs and reports, and preserve all evidence under a documented chain of custody to ensure integrity and legal admissibility.
Question
A payroll administrator noticed unexpected changes within a piece of software and reported the incident to the incident response team. Which actions should be taken at this step in the incident response workflow?
Options
- AClassify the criticality of the information, research the attacker's motives, and identify missing
- BDetermine the damage to the business, extract reports, and save evidence according to a chain
- CClassify the attack vector, understand the scope of the event, and identify the vulnerabilities being
- DDetermine the attack surface, evaluate the risks involved, and communicate the incident
How the community answered
(28 responses)- A11% (3)
- B82% (23)
- C4% (1)
- D4% (1)
Why each option
When an incident is first reported, the response team must immediately assess business damage, collect relevant logs and reports, and preserve all evidence under a documented chain of custody to ensure integrity and legal admissibility.
Researching attacker motives and classifying information criticality are threat intelligence activities that occur during later analytical phases, after evidence has already been secured.
Determining the damage to the business establishes incident severity and drives escalation decisions at the earliest stage of response. Extracting logs and reports captures volatile evidence before it is overwritten or lost, which is critical when software changes are the indicator of compromise. Maintaining a chain of custody from the moment evidence is collected ensures its integrity is preserved for any forensic investigation or potential legal proceedings.
Classifying the attack vector, understanding scope, and identifying vulnerabilities are deeper analysis tasks performed after initial evidence preservation and damage assessment are completed.
Determining the attack surface and evaluating risks are strategic activities associated with preparation and post-incident review phases, not the immediate triage actions taken when an incident is first detected.
Concept tested: Incident response detection phase - evidence preservation and damage assessment
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.