SSCP · Question #919
When a possible intrusion into your organization's information system has been detected, which of the following actions should be performed first?
The correct answer is C. Determine to what extent systems and data are compromised. Upon detecting a possible intrusion, the first action is to assess the scope and extent of the compromise. Without understanding what systems are affected, what data may be involved, and how far the intrusion has spread, you cannot make informed decisions about containment or…
Question
Options
- AEliminate all means of intruder access.
- BContain the intrusion.
- CDetermine to what extent systems and data are compromised.
- DCommunicate with relevant parties.
How the community answered
(42 responses)- A17% (7)
- B7% (3)
- C71% (30)
- D5% (2)
Explanation
Upon detecting a possible intrusion, the first action is to assess the scope and extent of the compromise. Without understanding what systems are affected, what data may be involved, and how far the intrusion has spread, you cannot make informed decisions about containment or eradication. Acting prematurely - such as cutting off access or eliminating means of entry - could tip off the intruder, destroy forensic evidence, or result in an incomplete response. Assessment comes first to guide all subsequent steps: containment, eradication, recovery, and communication.
Topics
Community Discussion
No community discussion yet for this question.