CAS-002 · Question #892
The IT Security Analyst for a small organization is working on a customer's system and identifies a possible intrusion in a database that contains PII. Since PII is involved, the analyst wants to…
The correct answer is D. Refer the issue to management for handling according to the incident response process. When a potential intrusion is identified, the analyst must follow the established incident response process before taking any independent action, even when PII is involved.
Question
The IT Security Analyst for a small organization is working on a customer's system and identifies a possible intrusion in a database that contains PII. Since PII is involved, the analyst wants to get the issue addressed as soon as possible. Which of the following is the FIRST step the analyst should take in mitigating the impact of the potential intrusion?
Options
- AContact the local authorities so an investigation can be started as quickly as possible.
- BShut down the production network interfaces on the server and change all of the DBMS account
- CDisable the front-end web server and notify the customer by email to determine how the customer
- DRefer the issue to management for handling according to the incident response process.
How the community answered
(32 responses)- A9% (3)
- B3% (1)
- C16% (5)
- D72% (23)
Why each option
When a potential intrusion is identified, the analyst must follow the established incident response process before taking any independent action, even when PII is involved.
Contacting authorities is a step within the IR process that must be authorized by management and legal counsel, not initiated unilaterally by the analyst.
Shutting down interfaces and changing DBMS credentials before authorization could destroy volatile forensic evidence and disrupt business operations without proper approval.
Disabling the web server and notifying the customer via email bypasses formal IR escalation and could inadvertently tip off an internal attacker or violate breach notification laws.
Incident response procedures exist precisely for situations like this - referring the issue to management ensures the organization follows its documented IR plan, maintains proper chain of custody, and authorizes subsequent actions legally and operationally. Acting unilaterally before escalation can violate legal obligations, destroy forensic evidence, or exceed the analyst's authority. The IR process will dictate containment, notification (including legal authorities and affected individuals), and remediation steps.
Concept tested: Incident response process - first step escalation
Source: https://www.nist.gov/publications/computer-security-incident-handling-guide
Topics
Community Discussion
No community discussion yet for this question.