CGRC · Question #353
What may Colvine Tech do if they determine that the root cause of an unauthorized change is an adversarial attack? Response:
The correct answer is D. All of the above. If an unauthorized change is found to be due to an adversarial attack, Colvine Tech should implement a comprehensive response.
Question
What may Colvine Tech do if they determine that the root cause of an unauthorized change is an adversarial attack? Response:
Options
- AImplement additional controls to reduce the risk of future attacks
- BAdjust intrusion detection and prevention system
- CInvoke incident response
- DAll of the above
How the community answered
(23 responses)- A17% (4)
- B9% (2)
- C4% (1)
- D70% (16)
Why each option
If an unauthorized change is found to be due to an adversarial attack, Colvine Tech should implement a comprehensive response.
Implementing additional controls is a critical step for long-term risk reduction but does not encompass the immediate incident handling or specific system adjustments needed.
Adjusting intrusion detection and prevention systems is important for improving real-time security, but it is one part of a broader incident response and mitigation strategy.
Invoking incident response is essential for immediate reaction to the attack, but it must be followed by or combined with measures to prevent recurrence and strengthen defenses.
All the listed actions are appropriate responses to an unauthorized change resulting from an adversarial attack. Invoking incident response is crucial for containment and recovery. Adjusting intrusion detection and prevention systems enhances future detection and prevention. Implementing additional controls helps to mitigate the risk of similar future attacks by strengthening overall security.
Concept tested: Incident response and post-incident actions
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.