GIAC
GCED · Question #7
GCED Question #7: Real Exam Question with Answer & Explanation
The correct answer is C. Search for sources of data and information that may be valuable in confirming and containing. See the full explanation below for the reasoning.
Question
Which tasks would a First Responder perform during the Identification phase of Incident Response?
Options
- AVerify the root cause of the incident and apply any missing security patches.
- BInstall or reenable host-based firewalls and anti-virus software on suspected systems.
- CSearch for sources of data and information that may be valuable in confirming and containing
- DDisconnect network communications and search for malicious executables or processes.
Community Discussion
No community discussion yet for this question.