300-215 Question 140
Select 3An organization has recently detected anomalous behavior in their network, which is suspected to be linked to a zero-day vulnerability. As part of the incident response process, they need to assess the risk and predict potential exploitation using AI-based tools. Which of the following actions should the organization prioritize to effectively manage this situation?
- A
Collect and analyze SIEM data to identify patterns of suspicious activity.
- B
Deploy a patch for the suspected zero-day vulnerability to all systems immediately.
- C
Leverage AI-based predictive models to assess the likelihood of exploitation.
- D
Perform a risk assessment to identify critical assets and prioritize response actions.
- E
Ignore the anomalous behavior until confirmation of the zero-day exploit is available.
Show answer and explanation
Correct answers: A, C, D
Explanation
Addressing zero-day vulnerabilities requires a proactive, multi-faceted approach. By collecting SIEM data, leveraging AI-based tools for predictive analysis, and conducting a thorough risk assessment, the organization can identify potential threats, estimate exploitation likelihood, and prioritize their response. Deploying patches for zero-day vulnerabilities is not an option as no patches exist initially, and ignoring anomalies can result in severe consequences.
- A. Correct.
Collecting and analyzing SIEM data helps in identifying behavioral patterns and correlating events that might indicate exploitation attempts or lateral movement associated with the zero-day vulnerability.
- B. Incorrect.
Deploying a patch immediately is not feasible for a zero-day vulnerability as no patch is available at this stage. Instead, mitigation strategies should be implemented.
- C. Correct.
AI-based predictive models can analyze threat intelligence and historical data to estimate the likelihood and impact of exploitation, helping in proactive defense.
- D. Correct.
Performing a risk assessment allows the organization to identify critical assets, understand potential impacts, and prioritize mitigation strategies appropriately.
- E. Incorrect.
Ignoring anomalous behavior is a poor practice as it may lead to undetected exploitation, causing significant damage to the organization.