100-160 Question 223
Single answerDuring a cybersecurity incident, a company's email server has been compromised, and sensitive data has been exfiltrated. As part of the incident handling process, what is the most appropriate first step to take?
- A
Disconnect the email server from the network to prevent further damage.
- B
Immediately notify law enforcement to report the security breach.
- C
Conduct a detailed forensic analysis of the server to determine the attack vector.
- D
Activate the incident response plan and follow the predefined steps.
Show answer and explanation
Correct answer: D
Explanation
The first step in responding to a cybersecurity incident is to activate the organization's incident response plan, which provides a structured framework for managing the situation. This ensures that all actions are coordinated, prioritized, and follow predefined protocols, minimizing the impact of the incident while preserving evidence for analysis.
- A. Incorrect.
Disconnecting the email server from the network can help contain the incident, but doing so without coordination can disrupt the investigation or recovery process.
- B. Incorrect.
Notifying law enforcement is important but should be done after the company follows its incident response plan and has gathered necessary information.
- C. Incorrect.
Conducting a forensic analysis is a critical step, but it should come after the initial activation of the incident response plan to ensure actions are properly prioritized and documented.
- D. Correct.
Activating the incident response plan ensures a structured approach to handling the incident, including containment, eradication, recovery, and communication.