CISM · Question #8
Which of the following should be done FIRST once a cybersecurity attack has been confirmed?
The correct answer is A. Isolate the affected system. Once a cybersecurity attack is confirmed, the very first step should be to isolate the affected system to prevent further compromise and contain the incident.
Question
Which of the following should be done FIRST once a cybersecurity attack has been confirmed?
Options
- AIsolate the affected system
- BPower down the system
- CNotify senior management
- DContact legal authorities
How the community answered
(26 responses)- A92% (24)
- C4% (1)
- D4% (1)
Why each option
Once a cybersecurity attack is confirmed, the very first step should be to isolate the affected system to prevent further compromise and contain the incident.
Isolating the affected system is crucial to prevent the attack from spreading to other systems or networks, thus limiting the scope and potential damage of the incident. This containment step helps preserve evidence and allows for more controlled analysis and remediation.
Powering down the system might destroy volatile data crucial for forensic analysis and could also disrupt critical business services, so isolation is generally preferred over immediate shutdown.
Notifying senior management is important, but containment (isolation) should precede notification to prevent further damage while management is being informed and plans are being made.
Contacting legal authorities is a later step in the incident response process, typically after initial containment, assessment, and potentially some investigation, when enough information is gathered to make such a report.
Concept tested: Incident response containment (first step)
Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.