GIAC
GCED · Question #33
An incident response team investigated a database breach, and determined it was likely the result of an internal user who had a default password in place. The password was changed. A week later…
The correct answer is D. They did not patch the database server after the event. You've hit your limit · resets 1pm (America/New_York)
Data Protection and Incident Response
Question
An incident response team investigated a database breach, and determined it was likely the result of an internal user who had a default password in place. The password was changed. A week later, they discover another loss of database records. The database admin provides logs that indicate the attack came from the front-end web interface. Where did the incident response team fail?
Options
- AThey did not eradicate tools left behind by the attacker
- BThey did not properly identify the source of the breach
- CThey did not lock the account after changing the password
- DThey did not patch the database server after the event
How the community answered
(36 responses)- A3% (1)
- B8% (3)
- C14% (5)
- D75% (27)
Explanation
You've hit your limit · resets 1pm (America/New_York)
Topics
#incident response#remediation#patching#root cause analysis
Community Discussion
No community discussion yet for this question.