300-215 Question 205
Select 3During a security incident involving unauthorized access to a corporate database, your team's response is guided by the typical goals of incident response. Which of the following actions align with these goals?
- A
Identify the origin and scope of the breach to contain the threat.
- B
Implement a complete system redesign without analyzing the incident.
- C
Preserve evidence to support legal or forensic investigations later.
- D
Communicate details of the incident to appropriate stakeholders.
- E
Ignore the incident if it does not appear to impact core business operations.
Show answer and explanation
Correct answers: A, C, D
Explanation
The goals of incident response include identifying and containing the threat, preserving evidence for forensic and legal purposes, and ensuring effective communication with stakeholders. These actions minimize damage, maintain organizational integrity, and prevent similar incidents in the future. Ignoring incidents or skipping analysis undermines these objectives.
- A. Correct.
Correct: Identifying the origin and scope is a foundational goal of incident response as it helps contain the threat and prevent further damage.
- B. Incorrect.
Incorrect: Implementing a system redesign without analyzing the incident skips critical steps like containment, investigation, and recovery, which are core to incident response.
- C. Correct.
Correct: Preserving evidence is crucial for forensic analysis and legal actions, ensuring that the root cause can be addressed and compliance requirements are met.
- D. Correct.
Correct: Communicating with stakeholders ensures transparency, aligns the response team with organizational priorities, and helps manage potential reputation risks.
- E. Incorrect.
Incorrect: Ignoring the incident, even if the impact isn't immediately apparent, contradicts the goals of incident response, which prioritize containment, analysis, and prevention of future incidents.