100-160 exam dumps

100-160 practice question 259 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 259

Select 4

A company has detected unauthorized access to its internal database containing sensitive customer information. As part of the incident response process, the cybersecurity team decides to follow a structured approach. Which steps should the company include in its incident response process to effectively manage this situation?

  1. A

    Identify and assess the scope of the incident

  2. B

    Eradicate the threat by removing unauthorized access and malicious components

  3. C

    Notify all employees to immediately change their passwords

  4. D

    Contain the incident to prevent further damage or spread

  5. E

    Conduct a post-incident analysis to improve future responses

Show answer and explanation

Correct answers: A, B, D, E

Explanation

Cybersecurity incident response involves a structured approach to handling security events. Key elements include identifying and assessing the incident, containing it to prevent further damage, eradicating the threat, and conducting a post-incident analysis to refine processes. Notifying employees to change passwords may be a necessary action in certain scenarios but is not a standard element of every incident response process.

  • A. Correct.

    Correct: Identifying and assessing the incident's scope is a critical first step in understanding the nature, impact, and extent of the cybersecurity event.

  • B. Correct.

    Correct: Eradicating the threat is a key part of the response process to ensure that the malicious activity is removed and cannot continue.

  • C. Incorrect.

    Incorrect: While notifying employees to change passwords may be necessary in some cases, it is not a core incident response step and depends on the specific context of the breach.

  • D. Correct.

    Correct: Containing the incident is crucial to limit its impact and prevent further damage or spread to other systems.

  • E. Correct.

    Correct: Conducting a post-incident analysis is essential to learn from the event and strengthen the organization’s security posture for future incidents.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam