CompTIA CySA+ CS0-003 Incident Response Activities Practice Test
Objective 3.2 • 40 original questions
This CompTIA CySA+ CS0-003 practice test focuses on objective 3.2: incident response activities. All questions are original ExamSnap scenarios aligned to the official CS0-003 objective set; they are not copied from live CompTIA exam content. Review every option explanation to understand why a choice fits or does not fit the scenario. For broader exam preparation, review the CompTIA CySA+ CS0-003 Exam Dumps page.
Instructions: Select the best answer unless the question explicitly says Select TWO or Select THREE. Review the explanation and option review after answering.
During an investigation at Tailspin Toys, the immediate requirement is to use observed malicious indicators to identify additional affected hosts. What should a SOC lead select? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: A
Why: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.
Option review:
A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.
B: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
C: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
D: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
E: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
Learning point: Use IoC-driven detection and analysis when the key requirement is to use observed malicious indicators to identify additional affected hosts.
At Proseware Research, a malware analyst has two simultaneous requirements: collect disk, memory, logs, or network evidence from an affected system, and determine how far the incident has spread before choosing containment actions. Which TWO options should be selected? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answers: C, E
Why: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system. Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
Option review:
A: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
C: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system.
D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
E: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
Learning point: Use Evidence acquisition, Scope determination when the key requirement is to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
For a managed cloud environment, the team must accomplish both of these goals: maintain an auditable record of every person who handled evidence, and estimate the business and technical consequences of the incident. Which TWO choices together provide the best match? The team wants the most defensible analyst action before expanding the investigation.
Correct answers: A, B
Why: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident. Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.
Option review:
A: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.
B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.
C: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.
D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.
E: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.
Learning point: Use Chain of custody, Impact assessment when the key requirement is to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.
In a high-value payment environment, a threat hunter must prove that an evidence image is unchanged after transfer and storage. Which approach is MOST appropriate? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: D
Why: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage.
Option review:
A: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage.
B: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage.
C: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage.
D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage.
E: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage.
Learning point: Use Evidence integrity validation when the key requirement is to prove that an evidence image is unchanged after transfer and storage.
A review at Humongous Insurance finds a gap: the team cannot reliably store acquired evidence so it remains intact for later analysis. Which option best closes that gap? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: B
Why: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.
Option review:
A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.
B: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.
C: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.
D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.
E: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.
Learning point: Use Evidence preservation when the key requirement is to store acquired evidence so it remains intact for later analysis.
a SOC analyst at Contoso Health is comparing several approaches. The deciding requirement is to prevent potentially relevant evidence from being deleted by normal retention rules. Which option should be chosen? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: C
Why: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.
Option review:
A: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.
B: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.
C: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.
D: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.
E: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.
Learning point: Use Legal hold when the key requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.
While supporting an airline operations network, a security operations engineer is asked to reconstruct what happened by correlating multiple telemetry sources. Which concept or tool is the clearest match? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: B
Why: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources.
Option review:
A: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.
B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources.
C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.
D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.
E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.
Learning point: Use Data and log analysis when the key requirement is to reconstruct what happened by correlating multiple telemetry sources.
A new security procedure at Lucerne Publishing must enable analysts to determine how far the incident has spread before choosing containment actions. Which option is the BEST choice? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: A
Why: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
Option review:
A: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
C: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
D: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
E: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
Learning point: Use Scope determination when the key requirement is to determine how far the incident has spread before choosing containment actions.
The primary objective for Fabrikam Finance is to estimate the business and technical consequences of the incident. Which selection best satisfies that objective in an online banking environment? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: C
Why: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.
Option review:
A: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
C: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.
D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
E: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
Learning point: Use Impact assessment when the key requirement is to estimate the business and technical consequences of the incident.
At City Power Utilities, an OT security analyst has two simultaneous requirements: stop a compromised endpoint from communicating with other systems, and maintain an auditable record of every person who handled evidence. Which TWO options should be selected? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answers: C, E
Why: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems. Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.
Option review:
A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems; maintain an auditable record of every person who handled evidence.
B: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems; maintain an auditable record of every person who handled evidence.
C: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems.
D: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems; maintain an auditable record of every person who handled evidence.
E: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.
Learning point: Use Isolation, Chain of custody when the key requirement is to stop a compromised endpoint from communicating with other systems; maintain an auditable record of every person who handled evidence.
During an investigation at A. Datum Logistics, the immediate requirement is to remove the root technical condition that allowed compromise. What should a security consultant select? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: D
Why: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.
Option review:
A: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
D: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.
E: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
Learning point: Use Remediation when the key requirement is to remove the root technical condition that allowed compromise.
Northwind Traders is updating its security operations standard for a regional distribution network. Which option most directly helps the team restore a heavily compromised endpoint to a known-good operating-system state? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: A
Why: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
Option review:
A: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.
C: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.
D: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.
E: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.
Learning point: Use Re-imaging when the key requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
A ticket at Alpine Ski House asks a cloud security analyst to reduce exposure temporarily while a full fix is being prepared. Which choice addresses the requirement most directly? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: D
Why: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.
Option review:
A: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
B: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
C: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
D: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.
E: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
Learning point: Use Compensating containment control when the key requirement is to reduce exposure temporarily while a full fix is being prepared.
In a branch-office network, a systems security analyst must use observed malicious indicators to identify additional affected hosts. Which approach is MOST appropriate? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: A
Why: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.
Option review:
A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.
B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
C: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
E: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
Learning point: Use IoC-driven detection and analysis when the key requirement is to use observed malicious indicators to identify additional affected hosts.
For a manufacturing plant, the team must accomplish both of these goals: collect disk, memory, logs, or network evidence from an affected system, and determine how far the incident has spread before choosing containment actions. Which TWO choices together provide the best match? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answers: A, E
Why: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system. Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
Option review:
A: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system.
B: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
C: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
D: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
E: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
Learning point: Use Evidence acquisition, Scope determination when the key requirement is to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
a security administrator at Fourth Coffee is comparing several approaches. The deciding requirement is to maintain an auditable record of every person who handled evidence. Which option should be chosen? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: A
Why: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.
Option review:
A: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.
B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence.
C: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence.
D: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence.
E: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence.
Learning point: Use Chain of custody when the key requirement is to maintain an auditable record of every person who handled evidence.
For a customer-facing messaging service, a response lead must satisfy all three needs: prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; and restore a heavily compromised endpoint to a known-good operating-system state. Select THREE. The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answers: B, C, D
Why: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions. Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state. Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage.
Option review:
A: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.
B: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
C: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage.
E: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.
Learning point: Use Evidence integrity validation, Scope determination, Re-imaging when the key requirement is to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.
A new security procedure at Adventure Works must enable analysts to store acquired evidence so it remains intact for later analysis. Which option is the BEST choice? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: A
Why: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.
Option review:
A: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.
B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.
C: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.
D: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.
E: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis.
Learning point: Use Evidence preservation when the key requirement is to store acquired evidence so it remains intact for later analysis.
The primary objective for Wide World Importers is to prevent potentially relevant evidence from being deleted by normal retention rules. Which selection best satisfies that objective in a global corporate network? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: D
Why: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.
Option review:
A: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.
B: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.
C: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.
D: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.
E: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules.
Learning point: Use Legal hold when the key requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.
Datum Fabrication is designing a combined control. It must reconstruct what happened by correlating multiple telemetry sources, and reduce exposure temporarily while a full fix is being prepared. Which TWO options are most appropriate? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answers: B, C
Why: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources. A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.
Option review:
A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources; reduce exposure temporarily while a full fix is being prepared.
B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources.
C: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.
D: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources; reduce exposure temporarily while a full fix is being prepared.
E: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources; reduce exposure temporarily while a full fix is being prepared.
Learning point: Use Data and log analysis, Compensating containment control when the key requirement is to reconstruct what happened by correlating multiple telemetry sources; reduce exposure temporarily while a full fix is being prepared.
During an investigation at Tailspin Toys, the immediate requirement is to determine how far the incident has spread before choosing containment actions. What should a SOC lead select? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: C
Why: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
Option review:
A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
C: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
D: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
Learning point: Use Scope determination when the key requirement is to determine how far the incident has spread before choosing containment actions.
Proseware Research is updating its security operations standard for a restricted research segment. Which option most directly helps the team estimate the business and technical consequences of the incident? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: A
Why: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.
Option review:
A: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.
B: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
C: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
D: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
E: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
Learning point: Use Impact assessment when the key requirement is to estimate the business and technical consequences of the incident.
A ticket at Wingtip Services asks a SOC analyst to stop a compromised endpoint from communicating with other systems. Which choice addresses the requirement most directly? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: D
Why: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems.
Option review:
A: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.
B: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.
C: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.
D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems.
E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.
Learning point: Use Isolation when the key requirement is to stop a compromised endpoint from communicating with other systems.
In a high-value payment environment, a threat hunter must remove the root technical condition that allowed compromise. Which approach is MOST appropriate? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: D
Why: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.
Option review:
A: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
B: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
C: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
D: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.
E: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
Learning point: Use Remediation when the key requirement is to remove the root technical condition that allowed compromise.
During a security review, a risk analyst must address two separate needs: restore a heavily compromised endpoint to a known-good operating-system state, and store acquired evidence so it remains intact for later analysis. Select TWO. The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answers: A, C
Why: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state. Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.
Option review:
A: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
B: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state; store acquired evidence so it remains intact for later analysis.
C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.
D: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state; store acquired evidence so it remains intact for later analysis.
E: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state; store acquired evidence so it remains intact for later analysis.
Learning point: Use Re-imaging, Evidence preservation when the key requirement is to restore a heavily compromised endpoint to a known-good operating-system state; store acquired evidence so it remains intact for later analysis.
a SOC analyst at Contoso Health is comparing several approaches. The deciding requirement is to reduce exposure temporarily while a full fix is being prepared. Which option should be chosen? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: C
Why: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.
Option review:
A: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
C: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.
D: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
E: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
Learning point: Use Compensating containment control when the key requirement is to reduce exposure temporarily while a full fix is being prepared.
While supporting an airline operations network, a security operations engineer is asked to use observed malicious indicators to identify additional affected hosts. Which concept or tool is the clearest match? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: B
Why: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.
Option review:
A: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
B: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.
C: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
D: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
Learning point: Use IoC-driven detection and analysis when the key requirement is to use observed malicious indicators to identify additional affected hosts.
Lucerne Publishing is designing a combined control. It must collect disk, memory, logs, or network evidence from an affected system, and determine how far the incident has spread before choosing containment actions. Which TWO options are most appropriate? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answers: B, D
Why: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system. Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
Option review:
A: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
B: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. It directly fits this scenario because the requirement is to collect disk, memory, logs, or network evidence from an affected system.
C: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
D: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
E: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
Learning point: Use Evidence acquisition, Scope determination when the key requirement is to collect disk, memory, logs, or network evidence from an affected system; determine how far the incident has spread before choosing containment actions.
During a security review, a vulnerability analyst must address two separate needs: maintain an auditable record of every person who handled evidence, and estimate the business and technical consequences of the incident. Select TWO. Assume the activity is authorized and must follow normal enterprise change control.
Correct answers: C, E
Why: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence. Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.
Option review:
A: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.
B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.
C: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. It directly fits this scenario because the requirement is to maintain an auditable record of every person who handled evidence.
D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.
E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.
Learning point: Use Chain of custody, Impact assessment when the key requirement is to maintain an auditable record of every person who handled evidence; estimate the business and technical consequences of the incident.
At City Power Utilities, the response plan has three distinct requirements: prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; and restore a heavily compromised endpoint to a known-good operating-system state. Which THREE options should be selected? Assume no additional product-specific features are available beyond the concepts listed.
Correct answers: A, C, D
Why: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions. Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage. Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
Option review:
A: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
B: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.
C: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. It directly fits this scenario because the requirement is to prove that an evidence image is unchanged after transfer and storage.
D: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
E: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.
Learning point: Use Evidence integrity validation, Scope determination, Re-imaging when the key requirement is to prove that an evidence image is unchanged after transfer and storage; determine how far the incident has spread before choosing containment actions; restore a heavily compromised endpoint to a known-good operating-system state.
For a newly acquired subsidiary, the team must accomplish both of these goals: store acquired evidence so it remains intact for later analysis, and remove the root technical condition that allowed compromise. Which TWO choices together provide the best match? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answers: C, E
Why: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis. Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.
Option review:
A: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis; remove the root technical condition that allowed compromise.
B: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis; remove the root technical condition that allowed compromise.
C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. It directly fits this scenario because the requirement is to store acquired evidence so it remains intact for later analysis.
D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to store acquired evidence so it remains intact for later analysis; remove the root technical condition that allowed compromise.
E: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.
Learning point: Use Evidence preservation, Remediation when the key requirement is to store acquired evidence so it remains intact for later analysis; remove the root technical condition that allowed compromise.
Northwind Traders is designing a combined control. It must prevent potentially relevant evidence from being deleted by normal retention rules, and restore a heavily compromised endpoint to a known-good operating-system state. Which TWO options are most appropriate? Base the decision on the primary security requirement, not on implementation convenience.
Correct answers: A, C
Why: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state. A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.
Option review:
A: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules; restore a heavily compromised endpoint to a known-good operating-system state.
C: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. It directly fits this scenario because the requirement is to prevent potentially relevant evidence from being deleted by normal retention rules.
D: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules; restore a heavily compromised endpoint to a known-good operating-system state.
E: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to prevent potentially relevant evidence from being deleted by normal retention rules; restore a heavily compromised endpoint to a known-good operating-system state.
Learning point: Use Legal hold, Re-imaging when the key requirement is to prevent potentially relevant evidence from being deleted by normal retention rules; restore a heavily compromised endpoint to a known-good operating-system state.
A ticket at Alpine Ski House asks a cloud security analyst to reconstruct what happened by correlating multiple telemetry sources. Which choice addresses the requirement most directly? The environment follows least privilege and preserves evidence where incident handling is involved.
Correct answer: C
Why: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources.
Option review:
A: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.
B: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.
C: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. It directly fits this scenario because the requirement is to reconstruct what happened by correlating multiple telemetry sources.
D: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.
E: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reconstruct what happened by correlating multiple telemetry sources.
Learning point: Use Data and log analysis when the key requirement is to reconstruct what happened by correlating multiple telemetry sources.
In a branch-office network, a systems security analyst must determine how far the incident has spread before choosing containment actions. Which approach is MOST appropriate? Use the choice that most directly addresses the stated evidence rather than a broader control.
Correct answer: A
Why: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
Option review:
A: Scoping identifies which systems, users, data, locations, and business processes are affected. It directly fits this scenario because the requirement is to determine how far the incident has spread before choosing containment actions.
B: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
D: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
E: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to determine how far the incident has spread before choosing containment actions.
Learning point: Use Scope determination when the key requirement is to determine how far the incident has spread before choosing containment actions.
A review at Litware Manufacturing finds a gap: the team cannot reliably estimate the business and technical consequences of the incident. Which option best closes that gap? The team wants the most defensible analyst action before expanding the investigation.
Correct answer: A
Why: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.
Option review:
A: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. It directly fits this scenario because the requirement is to estimate the business and technical consequences of the incident.
B: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
C: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
D: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
E: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to estimate the business and technical consequences of the incident.
Learning point: Use Impact assessment when the key requirement is to estimate the business and technical consequences of the incident.
a security administrator at Fourth Coffee is comparing several approaches. The deciding requirement is to stop a compromised endpoint from communicating with other systems. Which option should be chosen? Select based on the scenario’s decisive constraint, not on which technology is newest.
Correct answer: C
Why: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems.
Option review:
A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.
B: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.
C: Isolation contains an incident by separating affected systems or accounts from resources they could harm while preserving needed evidence. It directly fits this scenario because the requirement is to stop a compromised endpoint from communicating with other systems.
D: Impact analysis determines operational, confidentiality, integrity, availability, financial, legal, or reputational consequences. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.
E: Scoping identifies which systems, users, data, locations, and business processes are affected. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to stop a compromised endpoint from communicating with other systems.
Learning point: Use Isolation when the key requirement is to stop a compromised endpoint from communicating with other systems.
While supporting a customer-facing messaging service, a response lead is asked to remove the root technical condition that allowed compromise. Which concept or tool is the clearest match? Assume the activity is authorized and must follow normal enterprise change control.
Correct answer: D
Why: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.
Option review:
A: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
B: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
C: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
D: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. It directly fits this scenario because the requirement is to remove the root technical condition that allowed compromise.
E: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to remove the root technical condition that allowed compromise.
Learning point: Use Remediation when the key requirement is to remove the root technical condition that allowed compromise.
A new security procedure at Adventure Works must enable analysts to restore a heavily compromised endpoint to a known-good operating-system state. Which option is the BEST choice? Assume no additional product-specific features are available beyond the concepts listed.
Correct answer: D
Why: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
Option review:
A: Evidence acquisition collects relevant data using methods that preserve usefulness for investigation and possible legal review. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.
B: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.
C: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.
D: Re-imaging rebuilds a system from a trusted baseline when confidence in the existing installation cannot be restored. It directly fits this scenario because the requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
E: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to restore a heavily compromised endpoint to a known-good operating-system state.
Learning point: Use Re-imaging when the key requirement is to restore a heavily compromised endpoint to a known-good operating-system state.
The primary objective for Wide World Importers is to reduce exposure temporarily while a full fix is being prepared. Which selection best satisfies that objective in a global corporate network? The organization wants a vendor-neutral approach that can be explained during audit review.
Correct answer: A
Why: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.
Option review:
A: A compensating control reduces incident risk when permanent remediation cannot be applied immediately. It directly fits this scenario because the requirement is to reduce exposure temporarily while a full fix is being prepared.
B: Cryptographic hashes and documented procedures help demonstrate that collected evidence has not changed. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
D: Chain of custody documents who collected, transferred, stored, and accessed evidence from collection through disposition. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
E: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to reduce exposure temporarily while a full fix is being prepared.
Learning point: Use Compensating containment control when the key requirement is to reduce exposure temporarily while a full fix is being prepared.
At Datum Fabrication, a security architect needs to use observed malicious indicators to identify additional affected hosts. Which option is the BEST fit for a mixed Windows and Linux estate? Base the decision on the primary security requirement, not on implementation convenience.
Correct answer: E
Why: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.
Option review:
A: Remediation removes vulnerabilities, malicious artifacts, misconfigurations, or compromised credentials that enabled the incident. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
B: A legal hold suspends normal deletion or disposal for information relevant to anticipated or active litigation or investigation. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
C: Preservation protects evidence from alteration, loss, contamination, or unauthorized access. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
D: Correlating endpoint, identity, application, and network data builds a timeline and clarifies attacker actions. This can be useful in the right situation, but it does not most directly satisfy the scenario requirement to use observed malicious indicators to identify additional affected hosts.
E: Indicators of compromise help analysts identify affected systems and scope suspicious activity during detection and analysis. It directly fits this scenario because the requirement is to use observed malicious indicators to identify additional affected hosts.
Learning point: Use IoC-driven detection and analysis when the key requirement is to use observed malicious indicators to identify additional affected hosts.
Popular posts
Recent Posts
