CISA · Question #1
When an intrusion into an organization's network is detected, which of the following should be done FIRST?
The correct answer is B. Identify nodes that have been compromised.. Upon detecting a network intrusion, the immediate priority is to identify the scope of the compromise by determining which nodes have been affected.
Question
When an intrusion into an organization's network is detected, which of the following should be done FIRST?
Options
- AContact law enforcement.
- BIdentify nodes that have been compromised.
- CBlock all compromised network nodes.
- DNotify senior management
How the community answered
(27 responses)- A4% (1)
- B89% (24)
- C7% (2)
Why each option
Upon detecting a network intrusion, the immediate priority is to identify the scope of the compromise by determining which nodes have been affected.
Contacting law enforcement is an important step in incident response but typically follows initial assessment and containment, as concrete information is needed.
Before taking any containment or notification actions, it is crucial to understand the extent of the breach. Identifying compromised nodes allows the organization to accurately assess the impact, determine the attacker's foothold, and plan appropriate incident response steps effectively.
Blocking nodes prematurely without full identification could disrupt critical services or alert the attacker, hindering further investigation and eradication efforts.
Notifying senior management is essential for stakeholder awareness but should occur after initial assessment to provide them with a more accurate picture of the situation.
Concept tested: Incident response first steps, scope identification
Source: https://learn.microsoft.com/en-us/security/operations/incident-response-overview
Topics
Community Discussion
No community discussion yet for this question.