100-160 Question 259
Select 4A company has detected unauthorized access to its internal database containing sensitive customer information. As part of the incident response process, the cybersecurity team decides to follow a structured approach. Which steps should the company include in its incident response process to effectively manage this situation?
- A
Identify and assess the scope of the incident
- B
Eradicate the threat by removing unauthorized access and malicious components
- C
Notify all employees to immediately change their passwords
- D
Contain the incident to prevent further damage or spread
- E
Conduct a post-incident analysis to improve future responses
Show answer and explanation
Correct answers: A, B, D, E
Explanation
Cybersecurity incident response involves a structured approach to handling security events. Key elements include identifying and assessing the incident, containing it to prevent further damage, eradicating the threat, and conducting a post-incident analysis to refine processes. Notifying employees to change passwords may be a necessary action in certain scenarios but is not a standard element of every incident response process.
- A. Correct.
Correct: Identifying and assessing the incident's scope is a critical first step in understanding the nature, impact, and extent of the cybersecurity event.
- B. Correct.
Correct: Eradicating the threat is a key part of the response process to ensure that the malicious activity is removed and cannot continue.
- C. Incorrect.
Incorrect: While notifying employees to change passwords may be necessary in some cases, it is not a core incident response step and depends on the specific context of the breach.
- D. Correct.
Correct: Containing the incident is crucial to limit its impact and prevent further damage or spread to other systems.
- E. Correct.
Correct: Conducting a post-incident analysis is essential to learn from the event and strengthen the organization’s security posture for future incidents.