exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 1063 discussion

Actual exam question from CompTIA's SY0-501
Question #: 1063
Topic #: 1
[All SY0-501 Questions]

A newly hired Chief Security Officer (CSO) is reviewing the company's IRP and notices the procedures for zero-day malware attacks are being poorly executed, resulting in the CSIRT failing to address and coordinate malware removal from the system. Which of the following phases would BEST address these shortcomings?

  • A. Identification
  • B. Lessons learned
  • C. Recovery
  • D. Preparation
  • E. Eradication
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
fonka
3 years, 9 months ago
He is reading a procedure how the company mitigated the incident
upvoted 1 times
...
rudrasa
3 years, 10 months ago
zero-day malware attacks are being poorly executed ; that is already a lesson , so it is lesson learned
upvoted 2 times
...
monkeyyyyy
3 years, 11 months ago
My first thought was also Prepartion. But after further consideration, I change my mind to Lesson Learned. Here's my reasoning and please correct me if I'm wrong. Lessons learned. After personnel handles an incident, security personnel perform a lessons learned review. --> "(CSO) is reviewing the company's IRP " It’s very possible the incident provides some valuable lessons and the organization might modify procedures or add additional controls to prevent a reoccurrence of the incident. --> CSO “notices the procedures for zero-day malware attacks are being poorly executed” Gibson, Darril. CompTIA Security+ Get Certified Get Ahead: SY0-501 Study Guide (p. 493). Kindle Edition.
upvoted 4 times
...
Dion79
3 years, 11 months ago
Looks like lessons learned to me. I'd go with B. Preparation—making the system resilient to attack in the first place. This includes hardening systems, writing policies and procedures, and establishing confidential lines of communication. It also implies creating a formal incident response plan. Identification—determining whether an incident has taken place and assessing how severe it might be, followed by notification of the incident to stakeholders. Containment, Eradication, and Recovery—limiting the scope and impact of the incident. The typical response is to "pull the plug" on the affected system, but this is not always appropriate. Once the incident is contained, the cause can then be removed and the system brought back to a secure state. Lessons Learned—analyzing the incident and responses to identify whether procedures or systems could be improved. It is imperative to document the incident.
upvoted 1 times
...
Digger46
3 years, 11 months ago
Lessons learned are documented after an incident. We should not wait unit after an incident happens to make changes. Since an incident has not yet occurred, this is the Preparation phase, not the Lessons Learned phase.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago