An incident responder receives a call from a user who reports a computer is exhibiting symptoms consistent with a malware infection. Which of the following steps should the responder perform NEXT?
A.
Capture and document necessary information to assist in the response.
B.
Request the user capture and provide a screenshot or recording of the symptoms.
C.
Use a remote desktop client to collect and analyze the malware in real time.
D.
Ask the user to back up files for later recovery.
Analogy: If you are not feeling good and go to the doctor, what does the doctor ask you FIRST?
1. What is wrong with you.
2. Your symptoms.
3. He writes down the info.
Answer: A
Step 2) Detection and Analysis = Step 2) Identification
Again, this step is similar for both NIST and SANS, but with different verbiage.
At this point in the process, a security incident has been identified. This is where you go into research mode. Gather everything you can on the the incident. Then analyze it. Determine the entry point and the breadth of the breach. This process is made substantially easier and faster if you’ve got all your security tools filtering into a single location.
https://cybersecurity.att.com/blogs/security-essentials/incident-response-steps-comparison-guide
The first principle: "Preparation: This phase occurs before an incident and provides
guidance to personnel on how to respond to an incident.
upvoted 1 times
...
...
This section is not available anymore. Please use the main Exam Page.SY0-501 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Ales
Highly Voted 5 years, 9 months agobk45
5 years, 8 months agoKTakahashi
Most Recent 4 years, 1 month agoannarae
4 years, 3 months agoGuil
5 years, 1 month agoMarySK
5 years agokdce
5 years, 1 month agoSelienk
5 years, 2 months agoTada2005
5 years, 11 months agoAsmin
5 years, 11 months agonakres64
4 years, 5 months ago