exam questions

Exam CISSP-ISSAP All Questions

View all questions & answers for the CISSP-ISSAP exam

Exam CISSP-ISSAP topic 1 question 34 discussion

Actual exam question from ISC's CISSP-ISSAP
Question #: 34
Topic #: 1
[All CISSP-ISSAP Questions]

You work as an Incident handler in Mariotrixt.Inc. You have followed the Incident handling process to handle the events and incidents. You identify Denial of
Service attack (DOS) from a network linked to your internal enterprise network. Which of the following phases of the Incident handling process should you follow next to handle this incident?

  • A. Containment
  • B. Preparation
  • C. Recovery
  • D. Identification
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
74gjd_37
4 months, 2 weeks ago
A. Containment. Containment involves implementing measures to prevent further damage and minimize the impact of an incident. In the case of a DOS attack, this could involve isolating affected systems or networks, blocking traffic from known malicious IP addresses, adjusting firewall rules to filter out malicious traffic patterns, or utilizing load balancers to distribute incoming requests more effectively. Once containment has been achieved and immediate threats have been neutralized, the incident handler can then proceed to other phases such as identification (to determine how and why the incident occurred), recovery (to restore affected services or systems), and preparation (to implement preventive measures for future incidents). in this specific scenario where it has already been identified that the problem is a Denial of Service (DOS) attack, the next phase in the Incident handling process should not be Identification. Since you have already identified that it is a DOS attack from a network linked to your internal enterprise network, the next phase should indeed be A. Containment. The Containment phase involves taking immediate actions to mitigate and limit further damage caused by the incident, as mentioned earlier.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago