350-201 Question 7
Select 3You are a security analyst reviewing a playbook created for responding to phishing email incidents. The playbook includes the following components: identifying the malicious email, isolating affected endpoints, notifying affected users, and collecting evidence for further analysis. Which components of the playbook are essential for ensuring proper incident response and mitigation?
- A
Identifying the malicious email
- B
Isolating affected endpoints
- C
Notifying affected users
- D
Configuring network firewall rules
- E
Collecting evidence for further analysis
Show answer and explanation
Correct answers: A, B, E
Explanation
In an effective playbook, components must focus on immediate response actions to mitigate the attack, such as identification, containment, and evidence gathering. While notifying users and firewall configurations are important in broader security contexts, they are not directly critical to phishing mitigation in this scenario.
- A. Correct.
Identifying the malicious email is a critical first step to determine the scope and nature of the incident.
- B. Correct.
Isolating affected endpoints helps prevent the spread of the phishing attack, making it an essential mitigation step.
- C. Incorrect.
While notifying affected users is important, it is not a direct response or mitigation action in this specific incident context.
- D. Incorrect.
Configuring network firewall rules, while useful in other scenarios, is not directly relevant in most phishing email responses unless the attack involves malicious traffic.
- E. Correct.
Collecting evidence for further analysis ensures that the incident can be properly investigated and lessons learned for future prevention.