nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #131

You received an alert from Container Threat Detection that an added binary has been executed in a business critical workload. You need to investigate and respond to this incident. What should you…

The correct answer is A. Notify the workload owner. Follow the response playbook, and ask the threat hunting team to B. Review the finding, investigate the pod and related resources, and research the related attack. The correct response involves both notifying the workload owner and following the response playbook to ensure coordinated incident handling, and reviewing the finding while investigating the pod and related resources to understand the attack and determine the appropriate…

Incident Response and Investigation

Question

You received an alert from Container Threat Detection that an added binary has been executed in a business critical workload. You need to investigate and respond to this incident. What should you do? (Choose two.)

Options

  • ANotify the workload owner. Follow the response playbook, and ask the threat hunting team to
  • BReview the finding, investigate the pod and related resources, and research the related attack
  • CReview the finding, quarantine the cluster containing the running pod, and delete the running pod
  • DSilence the alert in the Security Command Center (SCC) console, as the alert is a low severity
  • EKeep the cluster and pod running, and investigate the behavior to determine whether the activity

How the community answered

(30 responses)
  • A
    77% (23)
  • C
    7% (2)
  • D
    3% (1)
  • E
    13% (4)

Explanation

The correct response involves both notifying the workload owner and following the response playbook to ensure coordinated incident handling, and reviewing the finding while investigating the pod and related resources to understand the attack and determine the appropriate remediation. This approach ensures proper communication, structured incident response, and thorough technical investigation without prematurely deleting or silencing critical evidence.

Topics

#Container Threat Detection#incident response#Security Command Center#container security

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice