nerdexam
Cisco

350-201 · Question #8

An engineer receives a report that indicates a possible incident of a malicious insider sending company information to outside parties. What is the first action the engineer must take to determine…

The correct answer is C. Analyze the precursors and indicators. The first step when a possible incident is reported is to analyze precursors and indicators to determine whether an actual incident has occurred, before escalating or taking further action.

Processes

Question

An engineer receives a report that indicates a possible incident of a malicious insider sending company information to outside parties. What is the first action the engineer must take to determine whether an incident has occurred?

Options

  • AAnalyze environmental threats and causes
  • BInform the product security incident response team to investigate further
  • CAnalyze the precursors and indicators
  • DInform the computer security incident response team to investigate further

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    89% (40)
  • D
    2% (1)

Why each option

The first step when a possible incident is reported is to analyze precursors and indicators to determine whether an actual incident has occurred, before escalating or taking further action.

AAnalyze environmental threats and causes

Analyzing environmental threats and causes is a post-confirmation activity that occurs after an incident is validated, not the first step in determining whether one occurred.

BInform the product security incident response team to investigate further

Informing the product security incident response team before confirming an incident risks misallocating resources and escalating prematurely based on an unverified report.

CAnalyze the precursors and indicatorsCorrect

Per the NIST SP 800-61 incident response lifecycle, the detection and analysis phase requires examining precursors - signs that an incident may occur - and indicators - signs that an incident is actively occurring or has occurred - before any other action is taken. For an insider threat report, this means reviewing data transfer logs, DLP alerts, email records, and access logs to find evidence that sensitive data was actually exfiltrated. Only after this analysis provides sufficient evidence can the team make an informed, justified decision about escalation and response.

DInform the computer security incident response team to investigate further

Notifying the CSIRT is an escalation action that should occur only after preliminary analysis confirms a credible incident, not as the very first investigative step.

Concept tested: Incident response detection and analysis - precursors and indicators

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response#insider threat#precursors and indicators#IR process

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice