Study sets
English

Information Security Management Examination (SG) | Section B Incident Response Case Questions 03

1 / 200.0s

Problem 1

Which is the first response, immediately on finding a PC that keeps communicating suspiciously with the outside, that limits the spread of infection and the loss of evidence?

View explanation

The answer is to isolate the device from the network, the first response on finding a PC that keeps communicating suspiciously with the outside that limits the spread of infection and the loss of evidence.

Problem 2

Which is the appropriate action when an employee realises they may have opened the attachment to a targeted mail?

View explanation

The answer is to contact the CSIRT through the reporting line, the appropriate action when an employee realises they may have opened the attachment to a targeted mail.

Problem 3

Which task, carried out before the investigation of a compromise begins, secures the later analysis and the evidential value?

View explanation

The answer is to preserve the logs and record the times, the task carried out before the investigation of a compromise begins that secures the later analysis and the evidential value.

Problem 4

Which is the countermeasure against business email compromise on receiving an urgent remittance request purporting to come from a partner's president?

View explanation

The answer is to confirm with the requester in person through another channel, the countermeasure against business email compromise on receiving an urgent remittance request purporting to come from a partner's president.

Problem 5

Which measure stops a leak spreading immediately after it is found that a confidential file was set to public by mistake?

View explanation

The answer is to disable the sharing link, the measure that stops a leak spreading immediately after it is found that a confidential file was set to public by mistake.

Problem 6

Which is the top priority when a cloud access key has been committed to a public repository by mistake?

View explanation

The answer is to revoke the API key and issue a new one, the top priority when a cloud access key has been committed to a public repository by mistake.

Problem 7

Which is an effective way of confirming that the backups can actually be used?

View explanation

The answer is to carry out restore drills for the backups regularly, an effective way of confirming that the backups can actually be used.

Problem 8

Which supplier risk measure should be taken before outsourcing the processing of personal information?

View explanation

The answer is to check the subcontractor's controls and the terms for further subcontracting, the supplier risk measure to be taken before outsourcing the processing of personal information.

Problem 9

Which control prevents access remaining when an employee leaves the company?

View explanation

The answer is to disable the account by the leaving date, the control that prevents access remaining when an employee leaves the company.

Problem 10

Which control is needed when the security standard is departed from temporarily for business reasons?

View explanation

The answer is to record the expiry of the exception and who approved it, the control needed when the security standard is departed from temporarily for business reasons.

Problem 11

Which is essential before carrying out penetration testing against the production environment?

View explanation

The answer is to obtain approval stating the scope and the purpose, the essential step before carrying out penetration testing against the production environment.

Problem 12

Which response applies when authentication failures have been frequent since an update and restoring the service takes priority over finding the cause?

View explanation

The answer is to roll the change back, the response when authentication failures have been frequent since an update and restoring the service takes priority over finding the cause.

Problem 13

How should the order of fixing be decided when several vulnerabilities are found at the same time?

View explanation

The answer is to prioritise by the extent of the impact and the importance, the way to decide the order of fixing when several vulnerabilities are found at the same time.

Problem 14

How should a security patch that is not urgent be rolled out to production safely?

View explanation

The answer is to confirm the effect in a test environment before applying it, the way to roll a security patch that is not urgent out to production safely.

Problem 15

Which practice curbs the misdirected mailing of confidential data preventively rather than after the event?

View explanation

The answer is to have an approver check the recipient, subject and attachments, the practice that curbs the misdirected mailing of confidential data preventively rather than after the event.

Problem 16

How can standing privileges be avoided when giving administrator rights to a maintenance contractor?

View explanation

The answer is to grant the rights automatically for only as long as they are needed, the way to avoid standing privileges when giving administrator rights to a maintenance contractor.

Problem 17

Which activity turns an incident response exercise into greater maturity?

View explanation

The answer is to revise the procedures based on the results of the drill, the activity that turns an incident response exercise into greater maturity.

Problem 18

Which preparation keeps the first communications possible even when ransomware has brought the internal systems down?

View explanation

The answer is to keep the contact list available offline as well, the preparation that keeps the first communications possible even when ransomware has brought the internal systems down.

Problem 19

Which measure guards against a leak when a company smartphone is lost with no prospect of recovering it?

View explanation

The answer is to wipe the data on the device remotely, the measure that guards against a leak when a company smartphone is lost with no prospect of recovering it.

Problem 20

Which activity confirms that the measures against recurrence are working, once a serious incident has been brought to a close?

View explanation

The answer is to re-evaluate the effectiveness of the controls on the basis of evidence, the activity that confirms the measures against recurrence are working once a serious incident has been brought to a close.