ExamGecko
Question list
Search
Search

Question 89 - CISM discussion

Report
Export

An online bank identifies a successful network attack in progress. The bank should FIRST:

A.
isolate the affected network segment.
Answers
A.
isolate the affected network segment.
B.
report the root cause to the board of directors.
Answers
B.
report the root cause to the board of directors.
C.
assess whether personally identifiable information (Pll) is compromised.
Answers
C.
assess whether personally identifiable information (Pll) is compromised.
D.
shut down the entire network.
Answers
D.
shut down the entire network.
Suggested answer: A

Explanation:

The online bank should first isolate the affected network segment, as this is the most effective way to contain the attack and prevent it from spreading to other parts of the network or compromising more data or systems. Isolating the affected network segment also helps to preserve the evidence and facilitate the investigation and recovery process.Reporting the root cause to the board of directors, assessing whether personally identifiable information (Pll) is compromised, and shutting down the entire network are not the first actions that the online bank should take, as they may not be feasible or appropriate at the time of the attack, and may cause more disruption, confusion, or damage to the business operations and reputation.Reference= CISM Review Manual 2023, page 1641; CISM Review Questions, Answers & Explanations Manual 2023, page 362; ISACA CISM - iSecPrep, page 213

asked 01/10/2024
Tony Hartzell
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first