ETExamTower
Q29Security Concepts

Which principle is applied when an analyst collects information relevant to a security incident to determine the appropriate course of action?

← → navigate · a answer
Community votes
D
71% (5)
A
29% (2)
B
0% (0)
C
0% (0)
Discussion · 18
3
"Decision-making" appears in NIST 800-600r2 in the Containment section, along with the term "appropriate strategy" which is similar to "appropriate course of action" as written in the question. "Organizations should create separate containment strategies for each major incident type, with criteria documented clearly to help ---decision-making----. Criteria for determining the appropriate strategy include...."
D 3
Selected Answer: D Cybersecurity due diligence is the process of anticipating, identifying, and addressing cyber risks across a company's network ecosystem.
D 3
Selected Answer: D Due diligence is the process of collecting and analyzing all relevant information before making a decision or taking action. In the context of security incidents, due diligence involves gathering and analyzing all available information about the incident, such as the nature of the threat, the extent of the damage or potential damage, and the possible impact on the organization's operations and assets. This information is then used to determine the appropriate course of action, such as containing and mitigating the threat, restoring systems and data, and identifying and addressing any underlying vulnerabilities
2
a is correct ,,since rapid response should be the first step not after gather and detict
A 2
Selected Answer: A Decision-making
2
A. decision making When an analyst gathers information relevant to a security incident, their main goal is to make informed decisions on how to proceed with the incident response. They need to assess the available data, understand the nature and severity of the incident, evaluate potential risks, and then decide on the right course of action to contain, mitigate, and remediate the situation effectively. "D. due diligence" is a broader concept that generally refers to the effort taken by a responsible party to avoid harm or possible risks to others. While due diligence is a critical part of the overall incident response process, the specific act of gathering information to determine the appropriate course of action aligns more closely with decision making (Option A) in this context.
D 2
Selected Answer: D The principle being followed when an analyst gathers information relevant to a security incident to determine the appropriate course of action is due diligence. Due diligence refers to the careful and thorough investigation and analysis of a particular situation or problem in order to make informed decisions or take appropriate action. In the context of security incidents, this may involve gathering and analyzing relevant data, studying the potential impact of the incident, and determining the most appropriate response based on the circumstances.
D 2
Selected Answer: D The correct answer is D. Due diligence. Due diligence refers to the amount of care and caution expected of individuals and organizations in order to protect themselves and others. In the context of security incidents, due diligence requires analysts to gather all relevant information about an incident in order to make informed decisions about the appropriate course of action. This involves carefully reviewing logs, network traffic, and other data sources to determine the scope and nature of the incident, and to identify any indicators of compromise.
1
Page29 on https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf The incident response team should move quickly to analyze and validate each incident, following a pre-defined process and documenting each step taken. When the team believes that an incident has occurred, the team should rapidly perform an initial analysis to determine the incident’s scope, such as which networks, systems, or applications are affected; who or what originated the incident; and how the incident is occurring (e.g., what tools or attack methods are being used, what vulnerabilities are being exploited). The initial analysis should give enough information for the team to prioritize later activities, such as containment of the incident and deeper analysis of the effects of the incident.
1
Option A is the best answer because the principle being described is decision making. When an analyst gathers information relevant to a security incident, they are collecting data to help them make an informed decision on how to proceed. Rapid response is related to how quickly an organization can respond to a security incident once it has been detected, while data mining involves the process of finding patterns in large datasets. Due diligence is a general term that refers to the effort that a reasonable person takes to avoid harm to others.
1
Dude diligence comes before decision making, you first due and gather all information about an incident then you start working on it to make your decisions.
1
DUE diligence, sorry for the typo
1
A : decision making
1
A : decision making due diligence is the right approach to gather information, now you need to decide on the course of action.
1
A. Decision-making
1
decision-making
1
D. due-diligence
A 1
Selected Answer: A The right answer is A. According to the Cisco CBROPS 200-201 curriculum, decision making is the main principle followed when an analyst gathers and evaluates information during a security incident. In a SOC environment, gathering relevant data (such as logs, traffic flows, and impact assessments) is not an end in itself; it is the prerequisite for determining the appropriate course of action. This process involves:Evaluation: Comparing the incident data against known baselines and security policies.Strategic Choice: Picking the most effective response (e.g., isolation, monitoring, or remediation) based on the analyzed severity and business context.Efficiency: Making sure the response is calculated to minimize damage while maintaining operational integrity.