The question has technically taken care of identification through detection. Further identification can be done after blocking all compromised nodes that were detected.
Blocking compromised network nodes helps to immediately contain the intrusion and prevent the attackers from accessing additional systems or causing further harm. This action buys time for the organization to assess the situation, identify the extent of the compromise, and formulate a comprehensive response plan, including identifying the compromised nodes (option B) in detail.
I think its B first then C, how could you block all compromised nodes without identifying them first? How will blocking compromised nodes help to identify the compromised nodes in detail?
Certainly, answer B is better. I was torn between answer D and B.
Identifying compromised nodes is crucial for understanding the scope of the intrusion and determining the appropriate response actions. Notifying senior management can follow once there is a clearer picture of the incident.
Notifying senior management when the ques asked in this way: What IT Auditor should do in the first place when this issue happens?
Add on why C is wrong: Prematurely blocking ALL compromised nodes could disrupt business operations and may not fully address the intrusion issue.
In the detection phase of incident management, we have to determine whether its a security incident or not
Ans:B. Identify nodes that have been compromised
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
macksonj
Highly Voted 3 months agoPumeza
Most Recent 1 week, 1 day ago1Naa
1 week, 3 days agomacksonj
1 month, 2 weeks agoB1990
4 months, 1 week agoSwallows
5 months, 2 weeks agoBosstate26
3 months, 3 weeks agohulisani
5 months, 1 week agoSwallows
4 months agokclow
3 months, 3 weeks agoa84n
6 months, 3 weeks ago5b56aae
7 months agondey926
1 year, 1 month agoChangwha
1 year, 4 months agoBankyz
1 year, 4 months ago