Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 212-89 Exam - Topic 5 Question 99 Discussion

A cybersecurity team at a financial services firm detects abnormal behavior on several endpoints, suggesting a possible breach. The anomalies include unexpected data transfers and processes running with unusual permissions. Given the potential impact, the team needs to quickly validate whether these are indicators of a security incident or benign anomalies. What method should the team prioritize to detect and validate the incident effectively?
A) Utilize an advanced behavioral analysis tool to differentiate between legitimate and malicious activities.
B) Implement strict access control measures to limit permissions on all endpoints immediately.
C) Disconnect the affected endpoints from the network to prevent potential data exfiltration.
D) Engage an external cybersecurity consultancy to conduct an independent assessment.

Eccouncil 212-89 Exam - Topic 5 Question 99 Discussion

Actual exam question for Eccouncil's 212-89 exam
Question #: 99
Topic #: 5
[All 212-89 Questions]

A cybersecurity team at a financial services firm detects abnormal behavior on several endpoints, suggesting a possible breach. The anomalies include unexpected data transfers and processes running with unusual permissions. Given the potential impact, the team needs to quickly validate whether these are indicators of a security incident or benign anomalies. What method should the team prioritize to detect and validate the incident effectively?

Show Suggested Answer Hide Answer
Suggested Answer: A

Explanation (aligned to IH&R lifecycle):

This question is about triage/validation---determining whether what you see is truly an incident and establishing priority. The most appropriate first move is to use endpoint telemetry and behavioral analytics (A) to validate maliciousness (e.g., suspicious parent/child process chains, token manipulation, credential dumping patterns, anomalous privilege escalation, and data transfer behaviors). This supports fast, evidence-based classification and reduces unnecessary disruption. Option (C) is containment and may be required after validation or for clearly high-confidence cases, but immediately disconnecting multiple endpoints can destroy volatile evidence, break business operations, and reduce your ability to trace lateral movement patterns across hosts. Option (B) is a broad preventive change that can create outage risk and is not a validation method. Option (D) can be helpful, but it is slower and not the primary ''detect and validate'' action for an internal team facing active anomalies.

A disciplined approach is: validate via behavioral tooling + logs, scope affected endpoints, determine severity, then execute containment proportional to confirmed risk. That sequencing mirrors standard incident handling flow (identify validate/triage contain eradicate recover lessons learned). When time matters, the highest-value action is the one that converts ambiguous signals into confident incident classification quickly---behavioral validation does that best.


Contribute your Thoughts:

0/2000 characters
Elbert
4 days ago
Engaging a consultancy (D) sounds expensive but could be worth it!
upvoted 0 times
...
Terry
9 days ago
I agree with A), but what if it misses something critical?
upvoted 0 times
...
Portia
14 days ago
Disconnecting endpoints (C) is a must to stop data leaks!
upvoted 0 times
...
Cathrine
19 days ago
Not sure if A) is enough, might need C) too.
upvoted 0 times
...
Huey
24 days ago
A) is the best choice for quick validation!
upvoted 0 times
...
Devon
29 days ago
I feel like implementing strict access controls is important, but it might be too late if the breach is already happening. We need to act fast!
upvoted 0 times
...
Fausto
1 month ago
Engaging an external consultancy sounds like a solid option, especially if we need an unbiased assessment, but I wonder if that would slow down our response time.
upvoted 0 times
...
Ramonita
1 month ago
I think disconnecting the endpoints could be a good immediate step to prevent further damage, but it might not help us validate if there's really a breach.
upvoted 0 times
...
Karma
1 month ago
I remember studying that behavioral analysis tools can help identify patterns, but I'm not sure if they can always distinguish between benign and malicious activities effectively.
upvoted 0 times
...

Save Cancel