A is correct. this training can help CSIRT to know whether to trigger IR mechanisms and reduce instances of false alert. With B - I don't really see why giving the IT team access can be beneficial, as this could very likely violate least privilege principle.
Any change after a comprise may not be possible. Only way to guarantee full access would be to modify before hand. Then you would violate principle of least privilege.
People who answered B
B. Modify access so the IT team has full access to the compromised assets.----> how do you know which are the compromised before they are compromised? The answer is A
Why do so many put so much faith in a human fed machine that learns by our own code that we teach it to learn from? The data sets used to educate an AI are literally fed by humans. Why would we put all faith in such a concept? It is cool and all and can help with my sports bets, but I cannot bargain my 380$ for ChatGPT, BARD or any other AI's opinions. Because in essence, AI, as a Deep/Machine Learning model only knows what we 'INSTRUCT' it too. From that instruction comes opinion and argument. Try it, they will argue with you. We can feed it all the data in the world but the MACHINE that LEARNS (which is coded by humans) has limits.
https://fortune.com/2023/07/19/chatgpt-accuracy-stanford-study/
The correct answer is A. Train the team to identify the difference between events and incidents.
Explanation:
- A well-prepared incident response process involves properly identifying and handling security events and incidents. Training the team to distinguish between events (normal activities that do not pose a security threat) and incidents (actual security breaches or potential threats) is crucial. This helps ensure that the team can focus on the real security incidents and respond effectively.
Why it's not B according to ChatGPT:
- Option B, modifying access so the IT team has full access to the compromised assets, is not a recommended action as it may lead to a conflict of interest and hinder proper investigation and containment. It is important to maintain the principle of least privilege and involve specialized incident response personnel.
Improving the incident response process involves various actions, but one recommended step is to train the team to differentiate between events and incidents. This training helps the team understand that not every event is necessarily an incident that requires immediate response and investigation. By being able to identify and classify events correctly, the team can focus their efforts on addressing actual incidents that pose a threat to the organization's security.
An event is defined as an attempt, successful or unsuccessful, to gain unauthorized access to, disrupt or misuse an Information System or information stored on such Information System.
An incident is defined as a breach of a system's security policy in order to affect its integrity or availability and/or the unauthorised access or attempted access to a system or systems
The Preparation (initial phase) involves correct data events are being logged, the reporting of potential incidents is happening and personnel training. Nothing in B, C and D is referring to that.
Of course the answer is "A", logically speaking, if the "CSIRT" and not "IT" team is trained to differentiate between events and incidents, that would drastically improve their IR process. 🐱🚀🐱💻
Also to add:
Security Incidents Are Events That Produce Consequences
It’s when an event results in a data breach or privacy breach that the event is then deemed a security incident.
For example, a delay in patching a security weakness in vital company software would be an event. It would only be deemed an incident after your security monitoring team confirmed a resulting data breach by hackers who capitalized on the weakness.
This section is not available anymore. Please use the main Exam Page.SY0-601 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
hazeleyes
Highly Voted 2 years, 8 months agovarun0
Highly Voted 2 years, 8 months agoBM9904
2 years, 8 months agocymm
2 years, 6 months agoMortG7
Most Recent 1 year, 6 months agovidwj
1 year, 9 months agoKraken84
1 year, 9 months agoProtract8593
1 year, 9 months agoKraken84
1 year, 9 months agoApplebeesWaiter1122
1 year, 10 months agoDALLASCOWBOYS
2 years, 3 months agoKingDrew
2 years, 4 months agookay123
2 years, 6 months agoGravoc
2 years, 7 months agocarpathia
2 years, 8 months agoj0n45
2 years, 8 months agoj0n45
2 years, 8 months agoMarceloFontes1979
2 years, 8 months agoLiftedkris
2 years, 8 months ago