nerdexam
CompTIA

CAS-003 · Question #355

At a meeting, the systems administrator states the security controls a company wishes to implement seem excessive, since all of the information on the company's web servers can be obtained publicly…

The correct answer is A. Refer to and follow procedures from the company's incident response plan. When a security incident occurs, the immediate first action must always be to activate the incident response plan to ensure a coordinated, documented, and legally sound response.

Enterprise Security Operations

Question

At a meeting, the systems administrator states the security controls a company wishes to implement seem excessive, since all of the information on the company's web servers can be obtained publicly and is not proprietary in any way. The next day the company's website is defaced as part of an SQL injection attack, and the company receives press inquiries about the message the attackers displayed on the website. Which of the following is the FIRST action the company should take?

Options

  • ARefer to and follow procedures from the company's incident response plan.
  • BCall a press conference to explain that the company has been hacked.
  • CEstablish chain of custody for all systems to which the systems administrator has access.
  • DConduct a detailed forensic analysis of the compromised system.
  • EInform the communications and marketing department of the attack details.

How the community answered

(32 responses)
  • A
    94% (30)
  • C
    3% (1)
  • E
    3% (1)

Why each option

When a security incident occurs, the immediate first action must always be to activate the incident response plan to ensure a coordinated, documented, and legally sound response.

ARefer to and follow procedures from the company's incident response plan.Correct

Following the incident response plan ensures that all subsequent actions - containment, evidence preservation, communication, and remediation - are performed in a coordinated, pre-approved sequence. Deviating from the IR plan risks destroying forensic evidence, making unauthorized public statements, or taking actions that create legal liability, all of which the plan is specifically designed to prevent.

BCall a press conference to explain that the company has been hacked.

Calling a press conference before following the IR plan could constitute an unauthorized disclosure and may conflict with legal, regulatory, or law enforcement requirements.

CEstablish chain of custody for all systems to which the systems administrator has access.

Establishing chain of custody for the sysadmin's systems is a forensic step that occurs within the IR process, not before it is initiated.

DConduct a detailed forensic analysis of the compromised system.

Forensic analysis of the compromised system is a phase of the IR process and should be performed under the plan's guidance, not as an ad hoc first action.

EInform the communications and marketing department of the attack details.

Informing the communications department is a notification task that the IR plan will direct at the appropriate time, not an independent first action.

Concept tested: Incident response plan activation as the first response step

Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r2.pdf

Topics

#incident response#web defacement#SQL injection#IR procedures

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice