An online trading company discovers that a network attack has penetrated the firewall. What should be the information security manager's FIRST response?
A.
Evaluate the impact to the business.
B.
Examine firewall logs to identify the attacker.
D. Implement mitigating controls.
When an online trading company discovers that a network attack has penetrated the firewall, the information security manager's first response should be to implement mitigating controls to contain and limit the scope of the attack as much as possible. This might include isolating the affected systems, shutting down or disconnecting compromised systems from the network, and implementing new firewall rules to block the attackers' IP addresses. This will help prevent the attackers from causing further damage, steal more data or spread the malware. After that, the information security manager can then evaluate the impact to the business, examine firewall logs to identify the attacker, and notify the regulatory agency of the incident.
The first part of the IR process is identifying and assessing the current state. An't do this without doing A. So (A) is the correct answer.
Rationale:
B. Knowing the attacker is great for attribution, but does little to address the issue
C. This should only be done once the threat/impact is fully understood
D. This should only be done once the threat/impact is fully understood
Following ISACA's own model below - A is the logical answer as it follows the analysis of the incident
https://www.isaca.org/resources/isaca-journal/issues/2020/volume-4/incident-response-models
Preparation
Detection and analysis
Containment, eradication and recovery
Postincident activity
D was my choice; in the real world you need to shut it down ASAP. Best way would be to invoke mitigating controls
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Broesweelies
Highly Voted 1 year, 10 months agoAaronS1990
1 year, 3 months agoiyke2k4
2 months, 3 weeks agoAlexJacobson
10 months agodark_3k03r
Highly Voted 1 year, 7 months agoyottabyte
Most Recent 8 months, 1 week agooluchecpoint
9 months, 2 weeks agosecdoc
1 year, 1 month agoAgamennore
1 year, 2 months agoAaronS1990
1 year, 3 months ago[Removed]
1 year, 4 months agochanke
1 year, 5 months agorichck102
1 year, 5 months agorichck102
1 year, 5 months agoRowlandmarc
1 year, 8 months agoWladysk
1 year, 9 months agocarbon232
1 year, 9 months ago