ExamGecko
Home Home / ISC / CISSP
Question list
Search
Search

Question 593 - CISSP discussion

Report
Export

A Security Operations Center (SOC) receives an incident response notification on a server with an active intruder who has planted a backdoor. Initial notifications are sent and communications are established.

What MUST be considered or evaluated before performing the next step?

A.
Notifying law enforcement is crucial before hashing the contents of the server hard drive
Answers
A.
Notifying law enforcement is crucial before hashing the contents of the server hard drive
B.
Identifying who executed the incident is more important than how the incident happened
Answers
B.
Identifying who executed the incident is more important than how the incident happened
C.
Removing the server from the network may prevent catching the intruder
Answers
C.
Removing the server from the network may prevent catching the intruder
D.
Copying the contents of the hard drive to another storage device may damage the evidence
Answers
D.
Copying the contents of the hard drive to another storage device may damage the evidence
Suggested answer: D
asked 18/09/2024
sangilipandy Arumugam
24 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first