350-201 · Question #8
An engineer receives a report that indicates a possible incident of a malicious insider sending company information to outside parties. What is the first action the engineer must take to determine…
The correct answer is C. Analyze the precursors and indicators. The first step when a possible incident is reported is to analyze precursors and indicators to determine whether an actual incident has occurred, before escalating or taking further action.
Question
An engineer receives a report that indicates a possible incident of a malicious insider sending company information to outside parties. What is the first action the engineer must take to determine whether an incident has occurred?
Options
- AAnalyze environmental threats and causes
- BInform the product security incident response team to investigate further
- CAnalyze the precursors and indicators
- DInform the computer security incident response team to investigate further
How the community answered
(45 responses)- A2% (1)
- B7% (3)
- C89% (40)
- D2% (1)
Why each option
The first step when a possible incident is reported is to analyze precursors and indicators to determine whether an actual incident has occurred, before escalating or taking further action.
Analyzing environmental threats and causes is a post-confirmation activity that occurs after an incident is validated, not the first step in determining whether one occurred.
Informing the product security incident response team before confirming an incident risks misallocating resources and escalating prematurely based on an unverified report.
Per the NIST SP 800-61 incident response lifecycle, the detection and analysis phase requires examining precursors - signs that an incident may occur - and indicators - signs that an incident is actively occurring or has occurred - before any other action is taken. For an insider threat report, this means reviewing data transfer logs, DLP alerts, email records, and access logs to find evidence that sensitive data was actually exfiltrated. Only after this analysis provides sufficient evidence can the team make an informed, justified decision about escalation and response.
Notifying the CSIRT is an escalation action that should occur only after preliminary analysis confirms a credible incident, not as the very first investigative step.
Concept tested: Incident response detection and analysis - precursors and indicators
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.