nerdexam
CompTIA

CAS-002 · Question #9

A data breach occurred which impacted the HR and payroll system. It is believed that an attack from within the organization resulted in the data breach. Which of the following should be performed…

The correct answer is A. Assess system status. The first step after a data breach is to assess the current system status to understand the scope and impact before taking any remediation action.

Enterprise Security

Question

A data breach occurred which impacted the HR and payroll system. It is believed that an attack from within the organization resulted in the data breach. Which of the following should be performed FIRST after the data breach occurred?

Options

  • AAssess system status
  • BRestore from backup tapes
  • CConduct a business impact analysis
  • DReview NIDS logs

How the community answered

(43 responses)
  • A
    84% (36)
  • B
    5% (2)
  • C
    2% (1)
  • D
    9% (4)

Why each option

The first step after a data breach is to assess the current system status to understand the scope and impact before taking any remediation action.

AAssess system statusCorrect

Assessing system status is the initial triage step in incident response - it determines which systems are compromised, what data was accessed, and whether the attacker still has access. Without this assessment, any subsequent action such as restoration or investigation may be premature, incomplete, or counterproductive. This aligns with NIST SP 800-61 incident response guidance, which prioritizes detection and analysis before containment and eradication.

BRestore from backup tapes

Restoring from backup tapes before assessing the breach could overwrite forensic evidence and is premature until the scope and nature of the compromise are understood.

CConduct a business impact analysis

A business impact analysis evaluates long-term effects and is a planning-phase activity, not the immediate first step during active incident response.

DReview NIDS logs

Reviewing NIDS logs is part of the investigation and analysis phase, but it is a component of the broader system status assessment rather than the overarching first action.

Concept tested: Incident response first steps - system status assessment

Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final

Topics

#incident response#data breach#system assessment#IR prioritization

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice