exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 64 discussion

Actual exam question from CompTIA's SY0-601
Question #: 64
Topic #: 1
[All SY0-601 Questions]

Which of the following actions would be recommended to improve an incident response process?

  • A. Train the team to identify the difference between events and incidents.
  • B. Modify access so the IT team has full access to the compromised assets.
  • C. Contact the authorities if a cybercrime is suspected.
  • D. Restrict communication surrounding the response to the IT team.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hazeleyes
Highly Voted 2 years, 8 months ago
Selected Answer: A
A is correct. this training can help CSIRT to know whether to trigger IR mechanisms and reduce instances of false alert. With B - I don't really see why giving the IT team access can be beneficial, as this could very likely violate least privilege principle.
upvoted 11 times
...
varun0
Highly Voted 2 years, 8 months ago
Selected Answer: B
B according to me
upvoted 5 times
BM9904
2 years, 8 months ago
I agree this step comes before training your team in the process
upvoted 2 times
...
cymm
2 years, 6 months ago
Any change after a comprise may not be possible. Only way to guarantee full access would be to modify before hand. Then you would violate principle of least privilege.
upvoted 4 times
...
...
MortG7
Most Recent 1 year, 6 months ago
People who answered B B. Modify access so the IT team has full access to the compromised assets.----> how do you know which are the compromised before they are compromised? The answer is A
upvoted 3 times
...
vidwj
1 year, 9 months ago
A is correct
upvoted 2 times
...
Kraken84
1 year, 9 months ago
Why do so many put so much faith in a human fed machine that learns by our own code that we teach it to learn from? The data sets used to educate an AI are literally fed by humans. Why would we put all faith in such a concept? It is cool and all and can help with my sports bets, but I cannot bargain my 380$ for ChatGPT, BARD or any other AI's opinions. Because in essence, AI, as a Deep/Machine Learning model only knows what we 'INSTRUCT' it too. From that instruction comes opinion and argument. Try it, they will argue with you. We can feed it all the data in the world but the MACHINE that LEARNS (which is coded by humans) has limits. https://fortune.com/2023/07/19/chatgpt-accuracy-stanford-study/
upvoted 1 times
...
Protract8593
1 year, 9 months ago
Selected Answer: A
The correct answer is A. Train the team to identify the difference between events and incidents. Explanation: - A well-prepared incident response process involves properly identifying and handling security events and incidents. Training the team to distinguish between events (normal activities that do not pose a security threat) and incidents (actual security breaches or potential threats) is crucial. This helps ensure that the team can focus on the real security incidents and respond effectively. Why it's not B according to ChatGPT: - Option B, modifying access so the IT team has full access to the compromised assets, is not a recommended action as it may lead to a conflict of interest and hinder proper investigation and containment. It is important to maintain the principle of least privilege and involve specialized incident response personnel.
upvoted 3 times
Kraken84
1 year, 9 months ago
https://fortune.com/2023/07/19/chatgpt-accuracy-stanford-study/
upvoted 2 times
...
...
ApplebeesWaiter1122
1 year, 10 months ago
Selected Answer: A
Improving the incident response process involves various actions, but one recommended step is to train the team to differentiate between events and incidents. This training helps the team understand that not every event is necessarily an incident that requires immediate response and investigation. By being able to identify and classify events correctly, the team can focus their efforts on addressing actual incidents that pose a threat to the organization's security.
upvoted 1 times
...
DALLASCOWBOYS
2 years, 3 months ago
A. Training team to differentiate between incidents and events,
upvoted 1 times
...
KingDrew
2 years, 4 months ago
Selected Answer: A
A is correct since it helps create more response efficiency.
upvoted 1 times
...
okay123
2 years, 6 months ago
Selected Answer: A
Training the team makes sense, I don't see how giving the whole IT team full access to zombie computers is going to do anything...
upvoted 3 times
...
Gravoc
2 years, 7 months ago
An event is defined as an attempt, successful or unsuccessful, to gain unauthorized access to, disrupt or misuse an Information System or information stored on such Information System. An incident is defined as a breach of a system's security policy in order to affect its integrity or availability and/or the unauthorised access or attempted access to a system or systems
upvoted 3 times
...
carpathia
2 years, 8 months ago
Selected Answer: A
The Preparation (initial phase) involves correct data events are being logged, the reporting of potential incidents is happening and personnel training. Nothing in B, C and D is referring to that.
upvoted 2 times
...
j0n45
2 years, 8 months ago
Of course the answer is "A", logically speaking, if the "CSIRT" and not "IT" team is trained to differentiate between events and incidents, that would drastically improve their IR process. 🐱‍🚀🐱‍💻
upvoted 3 times
j0n45
2 years, 8 months ago
Also to add: Security Incidents Are Events That Produce Consequences It’s when an event results in a data breach or privacy breach that the event is then deemed a security incident. For example, a delay in patching a security weakness in vital company software would be an event. It would only be deemed an incident after your security monitoring team confirmed a resulting data breach by hackers who capitalized on the weakness.
upvoted 3 times
...
...
MarceloFontes1979
2 years, 8 months ago
A - I believe is the best choice.
upvoted 2 times
...
Liftedkris
2 years, 8 months ago
Selected Answer: A
I’m leaning towards training so A for me
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago