ExamGecko
Question list
Search
Search

Question 625 - CISM discussion

Report
Export

Which of the following should be the FIRST step when performing triage of a malware incident?

A.
Containing the affected system
Answers
A.
Containing the affected system
B.
Preserving the forensic image
Answers
B.
Preserving the forensic image
C.
Comparing backup against production
Answers
C.
Comparing backup against production
D.
Removing the malware
Answers
D.
Removing the malware
Suggested answer: A

Explanation:

The first step when performing triage of a malware incident is to contain the affected system, which means isolating it from the network and preventing any further communication or data transfer with the attacker or other compromised systems. Containing the affected system helps to limit the scope and impact of the incident, preserve the evidence, and prevent the spread of the malware to other systems.

Reference=NIST SP 800-61 Revision 2,CISM Review Manual 15th Edition

asked 01/10/2024
Chris Carter
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first