200-201 Question 80
Select 3During an investigation of a potential data breach, the cybersecurity operations team is tasked with defining the scope of the incident. Which of the following actions are essential for accurately defining the scope?
- A
Identifying all affected systems and devices within the network
- B
Determining the intent of the attacker based on the initial evidence
- C
Establishing the timeline of the attack, including the start and end points
- D
Analyzing all network traffic for the past six months
- E
Documenting all compromised accounts and accessed resources
Show answer and explanation
Correct answers: A, C, E
Explanation
Defining the scope of an incident involves identifying all affected systems, establishing the timeline, and documenting compromised accounts and resources. These steps ensure a clear understanding of the breach's extent and impact, enabling effective containment and remediation.
- A. Correct.
Identifying all affected systems and devices is critical to understanding the full extent of the attack and ensuring that no compromised components are overlooked.
- B. Incorrect.
While determining the attacker's intent can be useful later in the investigation, it is not an essential step for defining the scope of the incident.
- C. Correct.
Establishing the timeline of the attack helps to understand when the breach started and ended, which is essential for defining the scope of the incident.
- D. Incorrect.
Analyzing all network traffic for the past six months is overly broad and impractical for defining the scope. The focus should be on the relevant data tied to the timeline and affected systems.
- E. Correct.
Documenting compromised accounts and accessed resources is necessary for understanding what data or assets were impacted, which is a key part of defining the scope.