exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 720 discussion

Actual exam question from CompTIA's SY0-501
Question #: 720
Topic #: 1
[All SY0-501 Questions]

A Chief Information Security Officer (CISO) has instructed the information assurance staff to act upon a fast-spreading virus.
Which of the following steps in the incident response process should be taken NEXT?

  • A. Identification
  • B. Eradication
  • C. Escalation
  • D. Containment
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Rajer
Highly Voted 4 years, 11 months ago
PICER-L Preparation Identification Containment Eradacation Recovery Lessons Learned
upvoted 18 times
...
iphy
Highly Voted 4 years, 10 months ago
key word here is "instructed to act upon on a fast spreading virus" with the options of answers available, identification is the first step in responding to the incidence with assumption that preparation was done already.
upvoted 9 times
...
Dion79
Most Recent 3 years, 11 months ago
I'd pick D, just saying. iphy is right about, "instructed to act upon a fast spreading virus" but one thing he was wrong on, this is one of two component of containment definition NOT the definition of identification. Now, when looking at the NIST, this also can be defined as an active identification, but I'm thinking CompTIA would add the word active since this is a reading comprehension certification, but who knows.... "Containment. Malware incident containment has two major components: stopping the spread of malware and preventing further damage to hosts. Nearly every malware incident requires containment actions. In addressing an incident, it is important for an organization to decide which methods of containment to employ initially, early in the response." "(Chief Information Security Officer) Typically, the job title of the person with overall responsibility for INFORMATION ASSURANCE assurance and systems security. Sometimes referred to as Chief Information Officer (CIO)". Link Below - NIST 800-83 Rev.1 document/PDF https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-83r1.pdf
upvoted 3 times
...
marvin_J
4 years ago
how does the CISO know its a virus? its already been identified as such. "act upon" tells me containment should be answer. because otherwise, you should go back to the very start, preparation. if i can't assume identification has been done, why are you assuming preparation has been done .
upvoted 6 times
...
simo77
4 years, 1 month ago
CISO find out there is a virus but don't know what type is it,so let identified which virus is it.
upvoted 1 times
...
L1singh
4 years, 1 month ago
Which systems have the virus, what is the damage done, which segment of the network is this on this all = identification which hasn't been done yet
upvoted 4 times
...
Not_My_Name
4 years, 6 months ago
I originally chose C, but now I'm thinking the answer is A as the team would first have to identify what systems are infected by the virus.
upvoted 4 times
...
CoRell
4 years, 8 months ago
D. Containment. It's a fast spreading virus, after all.
upvoted 6 times
...
xtf5x
4 years, 11 months ago
is it Escalation?
upvoted 1 times
...
burlatch
4 years, 11 months ago
Wouldn't this be containment since it was already identified by the CISO?
upvoted 4 times
MagicianRecon
4 years, 10 months ago
Thats fine but its a generic virus. Once the IR team is engaged they would need to Identify the issue, extent of it etc etc to be able to contain it.
upvoted 9 times
who__cares123456789___
4 years, 3 months ago
To all commenters, we know the chronological steps, our issue is the gray dividing line off when it has been identified!! I am assuming that if the given answer is correct, then you do not start containment until the virus has a Proper Name and a concrete scope is defined....would we start containment if the CISO says "DooDoo Virus-19", with malware signature DDS-134kv709 (made up name and sig) has been determined to reside on Hosts Wk15, Wk308, and Svr WebMaster10000?
upvoted 2 times
who__cares123456789___
4 years, 3 months ago
What I need to be able to determine is EXACTLY what all information I need to say "Well, we have Id'd this virus...NOW CONTAIN...Seems the dividing line between ID and CONTAIN is subjective...COMPTIA SUCKS!!
upvoted 4 times
...
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago