ExamGecko
Question list
Search
Search

Related questions

Question 152 - CISA discussion

Report
Export

When an intrusion into an organization network is deleted, which of the following should be done FIRST?

A.
Block all compromised network nodes.
Answers
A.
Block all compromised network nodes.
B.
Contact law enforcement.
Answers
B.
Contact law enforcement.
C.
Notify senior management.
Answers
C.
Notify senior management.
D.
Identity nodes that have been compromised.
Answers
D.
Identity nodes that have been compromised.
Suggested answer: D

Explanation:

The first thing that should be done when an intrusion into an organization network is detected is to identify nodes that have been compromised. Identifying nodes that have been compromised is a critical step in responding to an intrusion, as it helps determine the scope, impact, and source of the attack, and enables the implementation of appropriate containment and recovery measures. The other options are not the first things that should be done when an intrusion into an organization network is detected, as they may be premature or ineffective without identifying nodes that have been compromised. Blocking all compromised network nodes is a containment measure that can help isolate and prevent the spread of the attack, but it may not be possible or feasible without identifying nodes that have been compromised. Contacting law enforcement is a reporting measure that can help seek external assistance and comply with legal obligations, but it may not be necessary or appropriate without identifying nodes that have been compromised. Notifying senior management is a communication measure that can help inform and escalate the incident, but it may not be urgent or accurate without identifying nodes that have been compromised.Reference:CISA Review Manual (Digital Version), Chapter 4, Section 4.2.2

asked 18/09/2024
Leila Bekirova
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first