SK0-003 · Question #632
An administrator is investigating an incident where an unauthorized user gained access to a server and modified HR files. The administrator has a tested theory as to how the user accomplished this. Wh
The correct answer is C. Establish a plan of action to resolve the issue.. After identifying a tested theory for a security breach, the next step in incident response is to formulate a clear plan of action to address the issue, including containment, eradication, and recovery.
Question
An administrator is investigating an incident where an unauthorized user gained access to a server and modified HR files. The administrator has a tested theory as to how the user accomplished this. Which of the following actions should the administrator take NEXT?
Options
- APerform a root cause analysis.
- BImplement a change to the servers.
- CEstablish a plan of action to resolve the issue.
- DQuestion users prior to implementing the solution.
How the community answered
(23 responses)- A9% (2)
- B4% (1)
- C74% (17)
- D13% (3)
Why each option
After identifying a tested theory for a security breach, the next step in incident response is to formulate a clear plan of action to address the issue, including containment, eradication, and recovery.
Once an administrator has a tested theory regarding the cause of a security incident, the next step in the incident response process is to establish a comprehensive plan of action to resolve the issue, which includes containment, eradication, and recovery strategies. This ensures a structured and effective approach to remediation.
Questioning users might be part of the initial investigation phase to gather information, but once a tested theory of the incident's cause is established, the immediate next step is to plan the technical resolution.
Concept tested: Incident response planning
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.