SY0-501 · Question #459
A security analyst is investigating a potential reach. Upon gathering, documenting, and securing the evidence, which of the following actions is the NEXT step to minimize the business impact?
The correct answer is D. Remove malware and restore the system to normal operation. After evidence is gathered and secured during a breach investigation, the next priority is containment and recovery to minimize business impact by removing malware and restoring systems to normal operation.
Question
A security analyst is investigating a potential reach. Upon gathering, documenting, and securing the evidence, which of the following actions is the NEXT step to minimize the business impact?
Options
- ALaunch an investigation to identify the attacking host
- BInitiate the incident response plan
- CReview lessons learned captured in the process
- DRemove malware and restore the system to normal operation
How the community answered
(21 responses)- A5% (1)
- C10% (2)
- D86% (18)
Why each option
After evidence is gathered and secured during a breach investigation, the next priority is containment and recovery to minimize business impact by removing malware and restoring systems to normal operation.
Launching an investigation to identify the attacking host is a forensic/attribution task that occurs during analysis, not after evidence collection when business continuity is the priority.
Initiating the incident response plan would have already occurred before evidence gathering began, as evidence collection is itself a step within the incident response process.
Reviewing lessons learned is the final post-incident phase that takes place after the incident has been fully resolved and systems have been restored, not immediately after evidence collection.
Once evidence has been gathered, documented, and secured, the immediate next step to minimize business impact is remediation - removing malware and restoring affected systems to normal operation. This aligns with the incident response lifecycle where containment and eradication follow evidence collection, directly reducing downtime and limiting further damage to the organization.
Concept tested: Incident response lifecycle order and business impact minimization
Source: https://www.nist.gov/publications/computer-security-incident-handling-guide
Topics
Community Discussion
No community discussion yet for this question.