EC-Council
EC0-350 · Question #247
The intrusion detection system at a software development company suddenly generates multiple alerts regarding attacks against the company's external webserver, VPN concentrator, and DNS servers…
The correct answer is C. Investigate based on the potential effect of the incident. See the full explanation below for the reasoning.
Question
The intrusion detection system at a software development company suddenly generates multiple alerts regarding attacks against the company's external webserver, VPN concentrator, and DNS servers. What should the security team do to determine which alerts to check first?
Options
- AInvestigate based on the maintenance schedule of the affected systems.
- BInvestigate based on the service level agreements of the systems.
- CInvestigate based on the potential effect of the incident.
- DInvestigate based on the order that the alerts arrived in.
How the community answered
(42 responses)- A2% (1)
- B10% (4)
- C81% (34)
- D7% (3)
Community Discussion
No community discussion yet for this question.