SY0-501 · Question #2
An incident responder receives a call from a user who reports a computer is exhibiting symptoms consistent with a malware infection. Which of the following steps should the responder perform NEXT?
The correct answer is A. Capture and document necessary information to assist in the response. When responding to a potential malware incident, the first action is to capture and document relevant information to properly scope and guide the response effort.
Question
An incident responder receives a call from a user who reports a computer is exhibiting symptoms consistent with a malware infection. Which of the following steps should the responder perform NEXT?
Options
- ACapture and document necessary information to assist in the response.
- BRequest the user capture and provide a screenshot or recording of the symptoms
- CUse a remote desktop client to collect and analyze the malware m real time
- DAsk the user to back up files for later recovery
How the community answered
(44 responses)- A84% (37)
- B9% (4)
- C5% (2)
- D2% (1)
Why each option
When responding to a potential malware incident, the first action is to capture and document relevant information to properly scope and guide the response effort.
The initial step in any incident response process is identification and documentation - gathering details such as symptoms, affected systems, timestamps, and user actions. This information forms the foundation for all subsequent response steps (containment, eradication, recovery) and ensures evidence integrity is maintained from the outset per standard IR frameworks like NIST SP 800-61.
While screenshots can be useful, asking the user to capture evidence risks disrupting the system state, missing volatile data, or being done incorrectly; documentation should be led by the responder, not delegated to the end user as a first step.
Connecting via remote desktop during an active infection risks spreading malware, contaminating volatile memory evidence, and alerting the malware to analyst activity before proper containment and evidence collection procedures are established.
Asking the user to back up files before proper analysis could propagate malware to backup media, destroy forensic evidence, and violates the principle of preserving the original system state during the identification phase of incident response.
Concept tested: Incident response identification and documentation steps
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.