CAS-001 · Question #215
A data breach occurred which impacted the HR and payroll system. It is believed that an attack from within the organization resulted in the data breach. Which of the following should be performed…
The correct answer is A. Assess system status. The very first step after any security incident is to assess the current system status. You must determine the scope of compromise, whether the attack is still ongoing, which data was affected, and whether the system is stable or actively being exploited. Acting before this…
Question
A data breach occurred which impacted the HR and payroll system. It is believed that an attack from within the organization resulted in the data breach. Which of the following should be performed FIRST after the data breach occurred?
Options
- AAssess system status
- BRestore from backup tapes
- CConduct a business impact analysis
- DReview NIDS logs
How the community answered
(33 responses)- A73% (24)
- B18% (6)
- C3% (1)
- D6% (2)
Explanation
The very first step after any security incident is to assess the current system status. You must determine the scope of compromise, whether the attack is still ongoing, which data was affected, and whether the system is stable or actively being exploited. Acting before this assessment risks destroying evidence, making premature decisions, or missing an active threat. Restoring from backup (B) is premature and could overwrite forensic evidence. A BIA (C) is a pre-incident planning activity. Reviewing NIDS logs (D) is part of the investigation, but it follows the initial status assessment.
Topics
Community Discussion
No community discussion yet for this question.