Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-39 Exam - Topic 1 Question 124 Discussion

Sarah, a financial analyst at a multinational corporation, is suspected of leaking sensitive financial data to an unauthorized external party. The SOC team observed anomalous data transfer patterns originating from her account, flagged by the SIEM, indicating potential data exfiltration. The incident response team must contain the incident swiftly to minimize data loss and protect critical assets. As a SOC analyst, which should be prioritized as the initial containment measure?
A) Access control
B) Change passwords regularly
C) Isolate the storage
D) Data-Centric Audit and Protection (DCAP)

Eccouncil 312-39 Exam - Topic 1 Question 124 Discussion

Actual exam question for Eccouncil's 312-39 exam
Question #: 124
Topic #: 1
[All 312-39 Questions]

Sarah, a financial analyst at a multinational corporation, is suspected of leaking sensitive financial data to an unauthorized external party. The SOC team observed anomalous data transfer patterns originating from her account, flagged by the SIEM, indicating potential data exfiltration. The incident response team must contain the incident swiftly to minimize data loss and protect critical assets. As a SOC analyst, which should be prioritized as the initial containment measure?

Show Suggested Answer Hide Answer
Suggested Answer: A

Initial containment for suspected data exfiltration by a specific user account should prioritize immediately restricting that account's ability to access and transfer data. ''Access control'' is the broad containment category that includes disabling the account, suspending sessions, revoking tokens, removing access to sensitive shares, and applying conditional access blocks. This is the fastest way to stop ongoing data loss while preserving evidence for investigation. ''Change passwords regularly'' is a general security hygiene practice, not an initial incident containment action, and it may not stop exfiltration quickly if active sessions or tokens remain valid. ''Isolate the storage'' can be appropriate if a particular repository is being actively exfiltrated, but it can be disruptive to business operations and may not address the actor's continued access paths across other systems. DCAP is a programmatic capability for monitoring and controlling data access over time; it is valuable, but it is not the immediate first step when the SOC must rapidly stop suspected exfiltration. From a SOC playbook view, the initial action is to reduce attacker/insider access immediately (account restriction), then scope what data was accessed, preserve logs, and coordinate with HR/legal for insider procedures.


Contribute your Thoughts:

0/2000 characters
Janna
4 days ago
Not sure isolating storage is enough; what if the data's already out?
upvoted 0 times
...
Goldie
9 days ago
Access control should have been tighter from the start.
upvoted 0 times
...
Markus
14 days ago
Wow, I can't believe Sarah would do that!
upvoted 0 times
...
Fabiola
19 days ago
I think changing passwords regularly is important too, but not the priority here.
upvoted 0 times
...
Irving
24 days ago
Isolating the storage seems like the best first step.
upvoted 0 times
...
Ahmed
29 days ago
I wonder if Data-Centric Audit and Protection could help, but it seems like a longer-term solution rather than an immediate containment measure.
upvoted 0 times
...
Haley
1 month ago
This reminds me of a practice question where we had to prioritize containment measures. I feel like changing passwords regularly isn't enough in this case.
upvoted 0 times
...
Ronny
1 month ago
I'm not entirely sure, but I remember something about access control being important in these situations.
upvoted 0 times
...
Carmela
1 month ago
I think isolating the storage might be the best option here since it directly addresses the potential data exfiltration.
upvoted 0 times
...

Save Cancel