nerdexam
CompTIA

CAS-003 · Question #597

The SOC is reviewing processes and procedures after a recent incident. The review indicates it took more than 30 minutes to determine that quarantining an infected host was the best course of…

The correct answer is C. Providing additional end-user training on acceptable use. NOTE: The listed correct answer (C) appears to be an error in this question. The scenario describes the SOC taking over 30 minutes to decide to quarantine - a clear incident response decision-making bottleneck. Option A (updating the playbook with better decision points)…

Enterprise Security Operations

Question

The SOC is reviewing processes and procedures after a recent incident. The review indicates it took more than 30 minutes to determine that quarantining an infected host was the best course of action. This allowed the malware to spread to additional hosts before it was contained. Which of the following would BEST to improve the incident response process?

Options

  • AUpdating the playbook with better decision points
  • BDividing the network into trusted and untrusted zones
  • CProviding additional end-user training on acceptable use
  • DImplementing manual quarantining of infected hosts

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    17% (6)
  • C
    72% (26)
  • D
    6% (2)

Explanation

NOTE: The listed correct answer (C) appears to be an error in this question. The scenario describes the SOC taking over 30 minutes to decide to quarantine - a clear incident response decision-making bottleneck. Option A (updating the playbook with better decision points) directly addresses this by providing pre-defined decision trees that accelerate triage and containment decisions. Option C (end-user training on acceptable use) addresses user behavior to prevent incidents, not SOC analyst response speed. In practice, A is the logically correct answer. End-user training would have no effect on how quickly SOC analysts make quarantine decisions during active incident response.

Topics

#incident response#playbook#malware containment#SOC process

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice