CCCS-203B · Question #79
A security team at a multinational corporation detects suspicious activity on multiple cloud workloads protected by CrowdStrike Falcon Cloud Security. The team needs to properly report and escalate th
The correct answer is D. Generate a CrowdStrike Incident Report and escalate it through the organization's Security. Option A: Falcon RTR is a powerful tool for incident response, but immediate file deletion without forensic validation can lead to loss of evidence and potential operational impact. Security teams should analyze files before taking action. Option B: While isolating affected workl
Question
A security team at a multinational corporation detects suspicious activity on multiple cloud workloads protected by CrowdStrike Falcon Cloud Security. The team needs to properly report and escalate the incident for further investigation. What is the best course of action to take immediately?
Options
- AUse Falcon Real Time Response (RTR) to immediately delete all files suspected of being
- BShut down all affected cloud workloads immediately, even before conducting a forensic analysis.
- CDelete all security logs related to the incident to prevent attackers from covering their tracks.
- DGenerate a CrowdStrike Incident Report and escalate it through the organization's Security
How the community answered
(47 responses)- A19% (9)
- B6% (3)
- C4% (2)
- D70% (33)
Explanation
Option A: Falcon RTR is a powerful tool for incident response, but immediate file deletion without forensic validation can lead to loss of evidence and potential operational impact. Security teams should analyze files before taking action. Option B: While isolating affected workloads may be necessary, immediately shutting them down could erase critical forensic evidence. The best practice is to investigate the issue while maintaining logs and memory captures for further analysis. Option C: Deleting logs is a critical mistake. Security logs provide vital information for incident investigation, root cause analysis, and compliance reporting. Logs should be preserved and analyzed, not erased. Option D: Proper incident response requires documenting the event in an incident report and escalating it through the Security Operations Center (SOC). CrowdStrike Falcon provides detailed logging, detections, and forensic tools that should be used to investigate before taking additional remediation actions.
Topics
Community Discussion
No community discussion yet for this question.