ExamGecko
Question list
Search
Search

Question 118 - CISM discussion

Report
Export

What should be the FIRST step when an Internet of Things (loT) device in an organization's network is confirmed to have been hacked?

A.
Monitor the network.
Answers
A.
Monitor the network.
B.
Perform forensic analysis.
Answers
B.
Perform forensic analysis.
C.
Disconnect the device from the network,
Answers
C.
Disconnect the device from the network,
D.
Escalate to the incident response team
Answers
D.
Escalate to the incident response team
Suggested answer: C

Explanation:

= Disconnecting the device from the network is the first step when an IoT device in an organization's network is confirmed to have been hacked, as it prevents the attacker from further compromising the device or using it as a pivot point to attack other devices or systems on the network. Disconnecting the device also helps preserve the evidence of the attack for later forensic analysis and remediation.Disconnecting the device should be done in accordance with the incident response plan and the escalation procedures123.Reference=

1: CISM Review Manual 15th Edition, page 2004

2: CISM Practice Quiz, question 1072

3: IoT Security: Incident Response, Forensics, and Investigations, section ''IoT Incident Response''

asked 01/10/2024
rafael Flores
52 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first