100-160 Question 258
Select 3During a cybersecurity incident, your organization follows a structured incident response plan. Which of the following steps should be part of the incident response process to effectively handle the situation?
- A
Identify and document the scope of the incident
- B
Immediately delete affected systems to prevent further damage
- C
Contain the incident to limit its impact
- D
Restore affected systems to normal operations after analysis
- E
Communicate only within the IT team to avoid external attention
Show answer and explanation
Correct answers: A, C, D
Explanation
A structured cybersecurity incident response process typically includes steps such as identification, containment, eradication, recovery, and lessons learned. Actions such as documenting the scope, containing the incident, and restoring affected systems are critical for effective incident handling. Deleting systems prematurely or limiting communication to only the IT team can hinder the response process and lead to incomplete resolution or loss of important information.
- A. Correct.
Correct: Identifying and documenting the scope of the incident is a critical step in the incident response process to understand its impact and plan the response effectively.
- B. Incorrect.
Incorrect: Deleting affected systems without proper analysis can lead to loss of valuable forensic data and may not be the best course of action. Proper containment and investigation should be prioritized.
- C. Correct.
Correct: Containment is an essential step to prevent the incident from spreading further and to minimize its impact on the organization.
- D. Correct.
Correct: Restoring affected systems to normal operations is a key step after the incident has been analyzed and addressed, ensuring business continuity.
- E. Incorrect.
Incorrect: Communication during an incident should follow a defined communication strategy, which often involves informing stakeholders, management, and sometimes external entities, depending on the severity of the incident.