exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 462 discussion

Actual exam question from CompTIA's SY0-601
Question #: 462
Topic #: 1
[All SY0-601 Questions]

Which of the following incident response phases should the proper collection of the detected IoCs and establishment of a chain of custody be performed before?

  • A. Containment
  • B. Identification
  • C. Preparation
  • D. Recovery
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 1 year, 6 months ago
I had a stroke trying to read this question
upvoted 59 times
...
NetTech
Highly Voted 1 year, 10 months ago
Selected Answer: A
The wording of this question is tricky.
upvoted 19 times
zits88
1 year, 9 months ago
Yeah, even as a native English speaker this was hard, I can't imagine for others. I actually switched it around mentally to say "Which phase is after {all that stuff}". Made it a little easier
upvoted 12 times
CS3000
1 year, 9 months ago
I went over the question 5 times and I still don't understand. GL 2 me ^.^
upvoted 7 times
LongfellowDeeds
1 year, 3 months ago
Even my text-to-speech on my computer had a hard time getting it out
upvoted 3 times
...
...
...
...
AbdullahMohammad251
Most Recent 1 year, 1 month ago
Selected Answer: A
Question rephrased to comprehend it: Which of the following incident response phases should be performed after properly collecting the detected IoCs and establishing a chain of custody? Proper collection of IOCs(indicators of compromise) and a chain of custody is done in the 3rd step of an Incident response. These are the phases in order: Prepare > Identify > Contain > Eradicate > Recover > Review The answer is A. The next step after identifying a security incident is to contain the attack and prevent it from spreading!
upvoted 1 times
AbdullahMohammad251
1 year, 1 month ago
https://newsletter.stratussc.com/p/do-you-need-an-incident-response
upvoted 1 times
...
...
MortG7
1 year, 1 month ago
What a real world question? smh
upvoted 2 times
...
_deleteme_
1 year, 2 months ago
Before containment (the answer), the identification phase should establish the collection of indicators of compromise along with chain of custody. I'm going with A because of the fact that they said "BEFORE" collection. Comptia is really terrible for trying to trick people instead of allowing them to show knowledge of the study.
upvoted 2 times
...
alicia2024
1 year, 4 months ago
Selected Answer: B
The proper collection of Indicators of Compromise (IoCs) and the establishment of a chain of custody typically occur during the identification phase of incident response. During this phase, security teams detect and verify potential security incidents, gather evidence, and classify the incident based on its severity and impact. Containment, on the other hand, focuses on preventing further spread of the incident and minimizing its impact on the organization's systems and data.
upvoted 1 times
memodrums
1 year, 3 months ago
I agree, but the question states "be performed before" hence, its containment.
upvoted 1 times
...
...
cyberPunk28
1 year, 6 months ago
Selected Answer: A
A. Containment this wording is tricky confusing, I had to re-read this multiple times .
upvoted 2 times
...
bzona
1 year, 8 months ago
Selected Answer: A
Tricky question. I thought it was (B) Identification initially, but was wrong. Read carefully and you will get it. You cannot collect and establish anything before Identifying it, can you? Identify -> *collection and establishment Happens Here* -> Containment -> Eradication -> Recovery -> Lessons Learned.
upvoted 1 times
...
James_Tye
1 year, 8 months ago
The collection of IOCs (Indicators of Compromise) and establishment of chain of custody are part of the Detection and Analysis phase of the incident response process. In this phase, an organization detects and analyzes the incident to determine its scope, impact, and root cause. The collection of IOCs is a critical step in identifying the nature of the incident and determining the appropriate response. The establishment of chain of custody is also important to ensure that evidence is properly preserved and can be used in legal proceedings if necessary.
upvoted 1 times
...
sujon_london
1 year, 8 months ago
Selected Answer: A
Collecting IoCs and establishing a chain of custody is an essential step in the “Identification” phase of incident response. It involves gathering evidence and information about the incident, which is crucial for understanding the nature and scope of the security breach. Once this data has been collected and properly handled, the “Containment” phase follows to prevent further damage and mitigate the incident.
upvoted 1 times
...
rline63
1 year, 9 months ago
Kinda dumb because it happens before recovery as well. The way I thought about the question is obviously the latest step happens after this so might as well choose that. And I'm pretty sure it's correct but comp tia wants you to pick the step that happens immediately after yet they are too lazy to properly specify that in their wording.
upvoted 1 times
AbdullahMohammad251
1 year, 1 month ago
Yes but containment is done right after the identify phase, so A is the correct answer.
upvoted 2 times
...
...
AmesCB
1 year, 10 months ago
Selected Answer: B
I think what has been described is preparation, which comes before identification
upvoted 1 times
...
Selected Answer: A
Establishing a proper chain of custody for the collected evidence is crucial for the preservation of its integrity and admissibility in potential legal proceedings. Therefore, it is necessary to collect and maintain the evidence in a controlled and secure environment, ensuring that it remains unaltered and tamper-proof. This process should occur before the containment phase, where the security team isolates and limits the scope of the incident to prevent further damage or compromise to the systems or data.
upvoted 3 times
...
chocopiess
2 years, 1 month ago
Selected Answer: A
The keyword here is the word before, the collection of IoCs and establishment of chain of custody typically occurs during the identification phase, which is before the containment phase.
upvoted 11 times
...
staoic
2 years, 1 month ago
Selected Answer: A
The proper collection of the detected IoCs and establishment of a chain of custody should be performed before the Containment phase.
upvoted 1 times
...
fouserd
2 years, 1 month ago
Selected Answer: A
The proper collection of the detected IoCs and establishment of a chain of custody should be performed before the Containment phase of the incident response process. During the Containment phase, the goal is to prevent further damage or loss by isolating affected systems and preventing the spread of the incident. Proper collection of evidence and establishment of a chain of custody are important steps to ensure that any evidence collected during the incident response process is admissible in legal proceedings.
upvoted 1 times
...
mouettespaghetti
2 years, 1 month ago
The wording is vicious on this one, -A containment The proper collection of the detected IoCs and establishment of a chain of custody should be performed before the Containment phase in incident response.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...