nerdexam
GIAC

GCED · Question #33

An incident response team investigated a database breach, and determined it was likely the result of an internal user who had a default password in place. The password was changed. A week later…

The correct answer is D. They did not patch the database server after the event. You've hit your limit · resets 1pm (America/New_York)

Data Protection and Incident Response

Question

An incident response team investigated a database breach, and determined it was likely the result of an internal user who had a default password in place. The password was changed. A week later, they discover another loss of database records. The database admin provides logs that indicate the attack came from the front-end web interface. Where did the incident response team fail?

Options

  • AThey did not eradicate tools left behind by the attacker
  • BThey did not properly identify the source of the breach
  • CThey did not lock the account after changing the password
  • DThey did not patch the database server after the event

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    8% (3)
  • C
    14% (5)
  • D
    75% (27)

Explanation

You've hit your limit · resets 1pm (America/New_York)

Topics

#incident response#remediation#patching#root cause analysis

Community Discussion

No community discussion yet for this question.

Full GCED Practice