CRISC · Question #581
A user has contacted the risk practitioner regarding malware spreading laterally across the organization's corporate network. Which of the following is the risk practitioner's BEST course of action?
The correct answer is C. Notify the cybersecurity incident response team. When malware is actively spreading laterally across a corporate network, the risk practitioner's immediate and best course of action is to escalate the issue to the cybersecurity incident response team.
Question
A user has contacted the risk practitioner regarding malware spreading laterally across the organization's corporate network. Which of the following is the risk practitioner's BEST course of action?
Options
- AReview all log files generated during the period of malicious activity.
- BPerform a root cause analysis.
- CNotify the cybersecurity incident response team.
- DUpdate the risk register.
How the community answered
(15 responses)- A7% (1)
- B13% (2)
- C73% (11)
- D7% (1)
Why each option
When malware is actively spreading laterally across a corporate network, the risk practitioner's immediate and best course of action is to escalate the issue to the cybersecurity incident response team.
Reviewing log files is part of the investigation phase but not the immediate first action when active lateral movement is confirmed, as containment is paramount.
Performing a root cause analysis is a post-incident activity, done after the threat has been contained and eradicated, to prevent future occurrences.
Notifying the cybersecurity incident response team is the most critical immediate step when an active incident like malware spreading laterally is identified. This action initiates the formal incident response process, which includes containment, eradication, recovery, and post-incident analysis to mitigate the ongoing threat.
Updating the risk register is a risk management activity that follows an incident, incorporating lessons learned, but it doesn't address the immediate active threat.
Concept tested: Incident response initiation
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender/incident-response-overview
Topics
Community Discussion
No community discussion yet for this question.