Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-215 Exam - Topic 3 Question 88 Discussion

An incident response team is recommending changes after analyzing a recent compromise in which:a large number of events and logs were involved;team members were not able to identify the anomalous behavior and escalate it in a timely manner;several network systems were affected as a result of the latency in detection;security engineers were able to mitigate the threat and bring systems back to a stable state; andthe issue reoccurred shortly after and systems became unstable again because the correct information was not gathered during the initial identification phase.Which two recommendations should be made for improving the incident response process? (Choose two.)
C) Implement an automated operation to pull systems events/logs and bring them into an organizational context. and E) Modify the incident handling playbook and checklist to ensure alignment and agreement on roles, responsibilities, and steps before an incident occurs.
A) Formalize reporting requirements and responsibilities to update management and internal stakeholders throughout the incident-handling process effectively.
B) Improve the mitigation phase to ensure causes can be quickly identified, and systems returned to a functioning state.
D) Allocate additional resources for the containment phase to stabilize systems in a timely manner and reduce an attack's breadth.

Cisco 300-215 Exam - Topic 3 Question 88 Discussion

Actual exam question for Cisco's 300-215 exam
Question #: 88
Topic #: 3
[All 300-215 Questions]

An incident response team is recommending changes after analyzing a recent compromise in which:

a large number of events and logs were involved;

team members were not able to identify the anomalous behavior and escalate it in a timely manner;

several network systems were affected as a result of the latency in detection;

security engineers were able to mitigate the threat and bring systems back to a stable state; and

the issue reoccurred shortly after and systems became unstable again because the correct information was not gathered during the initial identification phase.

Which two recommendations should be made for improving the incident response process? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: C, E

Contribute your Thoughts:

0/2000 characters
Bette
9 months ago
Modifying the playbook is crucial for better alignment!
upvoted 0 times
...
Catarina
9 months ago
Allocating more resources sounds good, but will it really help?
upvoted 0 times
...
Basilia
10 months ago
Wait, how did they miss the anomalous behavior in the first place?
upvoted 0 times
...
Nada
10 months ago
I think formalizing reporting is a must too.
upvoted 0 times
...
Nell
10 months ago
Definitely need to implement automated logs collection!
upvoted 0 times
...
Gerald
10 months ago
Allocating more resources for containment sounds reasonable, but I wonder if modifying the playbook might be more effective in preventing confusion during incidents.
upvoted 0 times
...
Jaclyn
11 months ago
I feel like implementing automated operations for logs could really help with context. We had a similar practice question about streamlining data collection.
upvoted 0 times
...
Kristeen
11 months ago
I'm not entirely sure, but I think improving the mitigation phase could help. We practiced scenarios where quick identification of causes was crucial.
upvoted 0 times
...
Tonette
11 months ago
I remember discussing the importance of formalizing reporting requirements in our last class. It seems like a good way to keep everyone informed during an incident.
upvoted 0 times
...
Isadora
11 months ago
I'm a bit confused by all the details in the scenario, but I think the recommendations around improving the mitigation phase and allocating more resources for the containment phase could be good options to consider. I'll need to re-read the question carefully to make sure I'm on the right track.
upvoted 0 times
...
Hildred
11 months ago
Okay, I think I've got it. Implementing an automated system to pull system events and logs seems like a key recommendation to address the issue with not being able to identify the anomalous behavior in a timely manner. And modifying the incident handling playbook to ensure alignment on roles and responsibilities before an incident occurs would also be really important.
upvoted 0 times
...
Kelvin
11 months ago
This question seems to be focused on improving the incident response process, so I'll need to carefully consider the recommendations that address the issues mentioned in the scenario.
upvoted 0 times
...
Arletta
11 months ago
Hmm, this is a tricky one. I'm not entirely sure which two recommendations would be the best, but I think formalizing reporting requirements and responsibilities could be a good start to improve communication during the incident.
upvoted 0 times
...
Torie
2 years ago
Haha, I bet the security team wishes they had a 'Hack Undo' button for when things go wrong. Too bad that's not an actual option on the exam.
upvoted 0 times
Azzie
2 years ago
D) Allocate additional resources for the containment phase to stabilize systems in a timely manner and reduce an attack's breadth.
upvoted 0 times
...
Leatha
2 years ago
C) Implement an automated operation to pull systems events/logs and bring them into an organizational context.
upvoted 0 times
...
Maryann
2 years ago
B) Improve the mitigation phase to ensure causes can be quickly identified, and systems returned to a functioning state.
upvoted 0 times
...
Camellia
2 years ago
A) Formalize reporting requirements and responsibilities to update management and internal stakeholders throughout the incident-handling process effectively.
upvoted 0 times
...
...
Andra
2 years ago
I'd also consider B. Improving the mitigation phase to quickly identify and resolve the root cause is important to prevent the recurrence mentioned in the question.
upvoted 0 times
Cecilia
2 years ago
Allocating additional resources for the containment phase could help stabilize systems faster and reduce the impact of attacks.
upvoted 0 times
...
Jeanice
2 years ago
Yes, that's a good idea. We also need to improve the mitigation phase to quickly identify and resolve the root cause.
upvoted 0 times
...
Alyce
2 years ago
I think we should formalize reporting requirements and responsibilities to keep everyone updated.
upvoted 0 times
...
...
Sabine
2 years ago
I believe implementing an automated operation to pull system events/logs would be beneficial as well.
upvoted 0 times
...
Mila
2 years ago
I agree, C and E are the way to go. You can't rely on manual processes when you need to act fast during a breach. Automation is crucial.
upvoted 0 times
Esteban
2 years ago
Absolutely, manual processes can slow down response time. Automation and clear guidelines are key in incident response.
upvoted 0 times
...
Camellia
2 years ago
I agree with you. Automation can definitely speed up the process and having a clear playbook is essential.
upvoted 0 times
...
Hyun
2 years ago
E) Modify the incident handling playbook and checklist to ensure alignment and agreement on roles, responsibilities, and steps before an incident occurs.
upvoted 0 times
...
Van
2 years ago
C) Implement an automated operation to pull systems events/logs and bring them into an organizational context.
upvoted 0 times
...
...
Nickolas
2 years ago
Definitely go with C and E. Automating the log gathering process and updating the incident response playbook are key to avoiding the delays described in the scenario.
upvoted 0 times
Vincent
2 years ago
That sounds like a solid plan. Automating the log gathering process will definitely help speed up the response time.
upvoted 0 times
...
Aleisha
2 years ago
E) Modify the incident handling playbook and checklist to ensure alignment and agreement on roles, responsibilities, and steps before an incident occurs.
upvoted 0 times
...
Lavina
2 years ago
C) Implement an automated operation to pull systems events/logs and bring them into an organizational context.
upvoted 0 times
...
...
Kasandra
2 years ago
I agree with that. We also need to improve the mitigation phase for quick identification.
upvoted 0 times
...
Lezlie
2 years ago
I think we should formalize reporting requirements to keep everyone updated.
upvoted 0 times
...

Save Cancel