ExamGecko
Question list
Search
Search

Question 512 - CISM discussion

Report
Export

Which of the following should be done FIRST once a cybersecurity attack has been confirmed?

A.
Isolate the affected system.
Answers
A.
Isolate the affected system.
B.
Notify senior management.
Answers
B.
Notify senior management.
C.
Power down the system.
Answers
C.
Power down the system.
D.
Contact legal authorities.
Answers
D.
Contact legal authorities.
Suggested answer: A

Explanation:

Isolating the affected system is the first step in the incident response process, as it helps to contain the attack, prevent further damage, and preserve the evidence for analysis. Isolating the system can be done by disconnecting it from the network, blocking the malicious traffic, or applying quarantine rules.

Reference= CISM Review Manual 2022, page 3121; CISM Exam Content Outline, Domain 4, Task 4.22; Cybersecurity Incident Response Exercise Guidance3

asked 01/10/2024
Maurice Nicholson
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first