300-215 Question 204
Select 4During a cybersecurity incident, a Cisco SOC analyst is tasked with responding to a ransomware attack targeting an organization's critical systems. Which of the following accurately describe the primary goals of the incident response process in this scenario?
- A
Minimize the impact of the attack on business operations
- B
Identify and isolate the affected systems to prevent further spread
- C
Immediately restore all affected systems to their pre-attack state without detailed analysis
- D
Gather evidence to support legal or regulatory requirements
- E
Eradicate the malicious threat and recover the environment
Show answer and explanation
Correct answers: A, B, D, E
Explanation
The primary goals of incident response include minimizing impact, containing the threat, gathering evidence, eradicating the malicious activity, and recovering the environment. These steps ensure the organization can effectively manage the incident, reduce harm, and comply with legal or regulatory obligations. However, immediately restoring systems without proper analysis is counterproductive, as it risks the integrity of forensic evidence and might allow the threat to persist.
- A. Correct.
Minimizing the impact on business operations is a critical goal of incident response as it ensures the organization can maintain continuity and reduce potential losses.
- B. Correct.
Identifying and isolating affected systems helps contain the threat and prevents the attack from spreading to other systems, which is a key step in the incident response process.
- C. Incorrect.
Immediately restoring affected systems without detailed analysis is not a recommended practice because it risks overlooking critical forensic evidence and may allow the threat to persist.
- D. Correct.
Gathering evidence during an incident is crucial for supporting legal or regulatory requirements, as well as for post-incident analysis and accountability.
- E. Correct.
Eradicating the threat and recovering the environment ensure that the malicious activity is removed and the systems are restored to a secure state, aligning with the goals of incident response.