nerdexam
GIAC

GCED · Question #94

An incident response team is handling a worm infection among their user workstations. They created an IPS signature to detect and block worm activity on the border IPS, then removed the worm's…

The correct answer is B. The custom rule did not detect all infected workstations. Identifying and scoping an incident during triage is important to successfully handling a security incident. The detection methods used by the team didn't detect all the infected workstations.

Data Protection and Incident Response

Question

An incident response team is handling a worm infection among their user workstations. They created an IPS signature to detect and block worm activity on the border IPS, then removed the worm's artifacts or workstations triggering the rule. Despite this action, worm activity continued for days after. Where did the incident response team fail?

Options

  • AThe team did not adequately apply lessons learned from the incident
  • BThe custom rule did not detect all infected workstations
  • CThey did not receive timely notification of the security event
  • DThe team did not understand the worm's propagation method

How the community answered

(28 responses)
  • A
    21% (6)
  • B
    64% (18)
  • C
    4% (1)
  • D
    11% (3)

Explanation

Identifying and scoping an incident during triage is important to successfully handling a security incident. The detection methods used by the team didn't detect all the infected workstations.

Topics

#worm propagation#IPS signature#incident eradication#IR failure analysis

Community Discussion

No community discussion yet for this question.

Full GCED Practice