nerdexam
CompTIA

CAS-002 · Question #892

The IT Security Analyst for a small organization is working on a customer's system and identifies a possible intrusion in a database that contains PII. Since PII is involved, the analyst wants to…

The correct answer is D. Refer the issue to management for handling according to the incident response process. When a potential intrusion is identified, the analyst must follow the established incident response process before taking any independent action, even when PII is involved.

Enterprise Security

Question

The IT Security Analyst for a small organization is working on a customer's system and identifies a possible intrusion in a database that contains PII. Since PII is involved, the analyst wants to get the issue addressed as soon as possible. Which of the following is the FIRST step the analyst should take in mitigating the impact of the potential intrusion?

Options

  • AContact the local authorities so an investigation can be started as quickly as possible.
  • BShut down the production network interfaces on the server and change all of the DBMS account
  • CDisable the front-end web server and notify the customer by email to determine how the customer
  • DRefer the issue to management for handling according to the incident response process.

How the community answered

(32 responses)
  • A
    9% (3)
  • B
    3% (1)
  • C
    16% (5)
  • D
    72% (23)

Why each option

When a potential intrusion is identified, the analyst must follow the established incident response process before taking any independent action, even when PII is involved.

AContact the local authorities so an investigation can be started as quickly as possible.

Contacting authorities is a step within the IR process that must be authorized by management and legal counsel, not initiated unilaterally by the analyst.

BShut down the production network interfaces on the server and change all of the DBMS account

Shutting down interfaces and changing DBMS credentials before authorization could destroy volatile forensic evidence and disrupt business operations without proper approval.

CDisable the front-end web server and notify the customer by email to determine how the customer

Disabling the web server and notifying the customer via email bypasses formal IR escalation and could inadvertently tip off an internal attacker or violate breach notification laws.

DRefer the issue to management for handling according to the incident response process.Correct

Incident response procedures exist precisely for situations like this - referring the issue to management ensures the organization follows its documented IR plan, maintains proper chain of custody, and authorizes subsequent actions legally and operationally. Acting unilaterally before escalation can violate legal obligations, destroy forensic evidence, or exceed the analyst's authority. The IR process will dictate containment, notification (including legal authorities and affected individuals), and remediation steps.

Concept tested: Incident response process - first step escalation

Source: https://www.nist.gov/publications/computer-security-incident-handling-guide

Topics

#incident response#PII breach#escalation process#data breach handling

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice