ExamGecko
Home Home / ISC / CISSP
Question list
Search
Search

Question 598 - CISSP discussion

Report
Export

A security analyst for a large financial institution is reviewing network traffic related to an incident.

The analyst determines the traffic is irrelevant to the investigation but in the process of the review, the analyst also finds that an applications data, which included full credit card cardholder data, is transferred in clear text between the server and user's desktop. The analyst knows this violates the Payment Card Industry Data Security Standard (PCI-DSS). Which of the following is the analyst's next step?

A.
Send the log file co-workers for peer review
Answers
A.
Send the log file co-workers for peer review
B.
Include the full network traffic logs in the incident report
Answers
B.
Include the full network traffic logs in the incident report
C.
Follow organizational processes to alert the proper teams to address the issue.
Answers
C.
Follow organizational processes to alert the proper teams to address the issue.
D.
Ignore data as it is outside the scope of the investigation and the analyst's role.
Answers
D.
Ignore data as it is outside the scope of the investigation and the analyst's role.
Suggested answer: C
asked 18/09/2024
Floran Pikaar
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first