exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 270 discussion

Actual exam question from CompTIA's SY0-601
Question #: 270
Topic #: 1
[All SY0-601 Questions]

An organization is tuning SIEM rules based off of threat intelligence reports. Which of the following phases of the incident response process does this scenario represent?

  • A. Lessons learned
  • B. Eradication
  • C. Recovery
  • D. Preparation
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rodwave
Highly Voted 2 years, 5 months ago
Selected Answer: D
Answer: Preparation The preparation phase is when the organization is preparing for the attack. Tuning the SIEM is just providing the latest threat information to the system for preparation. ======================= Phases of the Incident Response Plan: 1. Preparation - Preparing for an attack and how to respond 2. Identification - Identifying the threat 3. Containment - Containing the threat 4. Eradication - Removing the threat 5. Recovery - Recovering affected systems 6. Lessons Learned - Evaluating the incident response, see where there can be improvements for a future incident.
upvoted 13 times
...
Jayysaystgis
Most Recent 6 months, 3 weeks ago
I say A. It saids. Based on reports. The incident happen before therefore so SIEM got tuned
upvoted 1 times
...
val4
1 year, 7 months ago
Why drop report? Its automatic app, always prepared to response any attack or i am wrong?
upvoted 1 times
...
ApplebeesWaiter1122
1 year, 10 months ago
Selected Answer: D
During the Preparation phase, an organization takes proactive steps to enhance its incident response capabilities and readiness. This includes activities such as tuning SIEM (Security Information and Event Management) rules based on threat intelligence reports. By analyzing and incorporating threat intelligence into the SIEM rules, the organization can enhance its ability to detect and respond to potential security incidents. The Preparation phase focuses on activities aimed at preventing and mitigating potential incidents, improving detection and response capabilities, and ensuring that necessary tools, processes, and resources are in place to effectively respond to security events. It involves tasks such as developing incident response plans, defining roles and responsibilities, establishing communication channels, implementing security controls, and conducting regular training and exercises.
upvoted 3 times
...
GetBuckets
2 years, 4 months ago
That’s D. Why? The organization learned about new threats/vulnerabilities from these threat intelligence reports that made them tune (tweak) their SIEM rules.
upvoted 4 times
...
nobnarb
2 years, 5 months ago
Selected Answer: D
They simply received intelligence reports. They are adjusting their defenses in PREPARATION for an attack. Now if this was after an attack then in would fall into the correction category.
upvoted 2 times
...
kindis
2 years, 5 months ago
Lessons learned A for me.
upvoted 3 times
...
comeragh
2 years, 6 months ago
Selected Answer: D
Agree with D here
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago