Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 212-89 Exam - Topic 5 Question 99 Discussion

A cybersecurity team at a financial services firm detects abnormal behavior on several endpoints, suggesting a possible breach. The anomalies include unexpected data transfers and processes running with unusual permissions. Given the potential impact, the team needs to quickly validate whether these are indicators of a security incident or benign anomalies. What method should the team prioritize to detect and validate the incident effectively?
A) Utilize an advanced behavioral analysis tool to differentiate between legitimate and malicious activities.
B) Implement strict access control measures to limit permissions on all endpoints immediately.
C) Disconnect the affected endpoints from the network to prevent potential data exfiltration.
D) Engage an external cybersecurity consultancy to conduct an independent assessment.

Eccouncil 212-89 Exam - Topic 5 Question 99 Discussion

Actual exam question for Eccouncil's 212-89 exam
Question #: 99
Topic #: 5
[All 212-89 Questions]

A cybersecurity team at a financial services firm detects abnormal behavior on several endpoints, suggesting a possible breach. The anomalies include unexpected data transfers and processes running with unusual permissions. Given the potential impact, the team needs to quickly validate whether these are indicators of a security incident or benign anomalies. What method should the team prioritize to detect and validate the incident effectively?

Show Suggested Answer Hide Answer
Suggested Answer: A

Explanation (aligned to IH&R lifecycle):

This question is about triage/validation---determining whether what you see is truly an incident and establishing priority. The most appropriate first move is to use endpoint telemetry and behavioral analytics (A) to validate maliciousness (e.g., suspicious parent/child process chains, token manipulation, credential dumping patterns, anomalous privilege escalation, and data transfer behaviors). This supports fast, evidence-based classification and reduces unnecessary disruption. Option (C) is containment and may be required after validation or for clearly high-confidence cases, but immediately disconnecting multiple endpoints can destroy volatile evidence, break business operations, and reduce your ability to trace lateral movement patterns across hosts. Option (B) is a broad preventive change that can create outage risk and is not a validation method. Option (D) can be helpful, but it is slower and not the primary ''detect and validate'' action for an internal team facing active anomalies.

A disciplined approach is: validate via behavioral tooling + logs, scope affected endpoints, determine severity, then execute containment proportional to confirmed risk. That sequencing mirrors standard incident handling flow (identify validate/triage contain eradicate recover lessons learned). When time matters, the highest-value action is the one that converts ambiguous signals into confident incident classification quickly---behavioral validation does that best.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel