200-201 Question 79
Single answerA cybersecurity analyst is tasked with investigating a potential data breach that occurred in the organization’s network. The analyst is directed to identify the systems impacted, the type of data involved, and the extent of the intrusion. Which of the following best describes the analyst’s responsibility in terms of defining the scope of the investigation?
- A
Determine the affected systems and compile a list of all network assets.
- B
Identify the data involved, systems affected, and the boundaries of the intrusion.
- C
Focus only on identifying the malware used during the attack and the method of entry.
- D
Examine all systems within the organization, regardless of their connection to the breach.
Show answer and explanation
Correct answer: B
Explanation
Defining the scope of a cybersecurity investigation is a critical step to ensure the investigation remains focused and efficient. It involves identifying the systems and data impacted by the incident, as well as clearly outlining the boundaries of the intrusion. This helps avoid unnecessary efforts and ensures the analyst addresses the most relevant aspects of the breach.
- A. Incorrect.
This option is incorrect because compiling a list of all network assets is not directly related to defining the scope of the investigation. Instead, it is more relevant to asset management or inventory tasks.
- B. Correct.
This option is correct because defining the scope involves determining the systems impacted, the type of data involved, and the extent of the intrusion. It ensures the investigation stays focused on the relevant areas.
- C. Incorrect.
This option is incorrect because focusing solely on malware or the method of entry does not fully define the scope. The scope must encompass all aspects of the breach, not just the attack vector.
- D. Incorrect.
This option is incorrect because examining all systems within the organization, regardless of their connection to the breach, is inefficient and outside the proper scope of the investigation. The scope should be limited to systems and data relevant to the incident.