exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 253 discussion

Actual exam question from CompTIA's SY0-601
Question #: 253
Topic #: 1
[All SY0-601 Questions]

Which of the following in the incident response process is the BEST approach to improve the speed of the identification phase?

  • A. Activate verbose logging in all critical assets.
  • B. Tune monitoring in order to reduce false positive rates.
  • C. Redirect all events to multiple syslog servers.
  • D. Increase the number of sensors present on the environment.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Sir_Learnalot
Highly Voted 2 years, 5 months ago
Selected Answer: B
In the incident response process the identification phase is used to recognize whether an event that occurs should be classified as an incident. Therefor false positive tuning would increase the identification time, as A and D would give you more insides, but also more FP and there fore it makes it harder to identify real incidents...I´ll go with "B"
upvoted 16 times
...
ronniehaang
Highly Voted 2 years, 2 months ago
Selected Answer: B
B. Tune monitoring in order to reduce false positive rates. Improving the speed of the identification phase in incident response process involves reducing the amount of data that has to be analyzed to find the incident. Tuning monitoring to reduce false positive rates helps to achieve this goal by reducing the amount of noise in the logs and alerts that have to be analyzed. This means that only the most relevant data is being evaluated, which can significantly reduce the time it takes to identify an incident and move to the next phase of the incident response process. By tuning the monitoring to reduce false positive rates, the systems administrator can focus on only the most important data, which can help to speed up the identification phase and improve overall incident response time.
upvoted 5 times
...
ApplebeesWaiter1122
Most Recent 1 year, 9 months ago
Selected Answer: B
Reducing false positive rates in monitoring and alerting systems helps to minimize the noise and focus on relevant alerts. By fine-tuning the monitoring rules and thresholds, the security team can filter out non-critical or irrelevant alerts, allowing them to quickly identify genuine security incidents that require immediate attention. This optimization ensures that the incident response team can focus on real threats and avoid wasting time on false alarms, ultimately improving the speed and effectiveness of the identification phase.
upvoted 5 times
...
Yawannawanka
2 years ago
Selected Answer: B
Tuning monitoring in order to reduce false positive rates is the BEST approach to improve the speed of the identification phase in the incident response process. By reducing false positives, security analysts can focus on investigating and responding to actual security incidents, rather than spending time on false alarms. This can help speed up the identification phase by allowing analysts to quickly identify and respond to real security incidents. Activating verbose logging in all critical assets, redirecting all events to multiple syslog servers, and increasing the number of sensors present on the environment can also be helpful, but may not have as much of an impact on the speed of the identification phase as tuning monitoring to reduce false positives.
upvoted 2 times
...
Bogardinc
2 years, 2 months ago
I believe some of you guys have dedicated your lives to input wrong answers to throw everyone off. If you don't have a reference please knock it off.
upvoted 2 times
omen679
2 years, 2 months ago
What is the correct answer?
upvoted 4 times
...
...
G4ct756
2 years, 6 months ago
Selected Answer: B
B, getting accurate report will allow analyst to pinpoint the problem fast. not A, cause there is no point focusing on Critical Asset when point of entry is likely some host. not C, cause having your logs distributed makes it harder to aggregate. not d, more sensor will produce more log for analyst to sift through.
upvoted 2 times
...
ostralo
2 years, 6 months ago
Selected Answer: A
FP alerts cost too much time..
upvoted 1 times
ostralo
2 years, 6 months ago
Oh no... I meant to choose B
upvoted 1 times
ostralo
2 years, 6 months ago
A,D will worsen the speed of the identification phase
upvoted 1 times
...
...
...
nk020
2 years, 6 months ago
Selected Answer: A
should be A
upvoted 1 times
...
jspecht
2 years, 6 months ago
Selected Answer: A
Verbose logging will give you a better idea of exactly what is going on in your environment.
upvoted 2 times
yasuke
2 years, 6 months ago
verbose logging can also give false +ves if not tuned well
upvoted 3 times
...
...
Granddude
2 years, 6 months ago
Selected Answer: D
After reading this article, I believe detection is the key. https://www.sciencedirect.com/topics/computer-science/incident-response-process
upvoted 4 times
Papee
2 years, 6 months ago
Read the article nothing about increasing sensor on environment was mentioned for Identification Phase. Any better explanation?
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago