An incident response team is handling a worm infection among their user workstations. They created an IPS signature to detect and block worm activity on the border IPS, then removed the worm's artifacts or workstations triggering the rule. Despite this action, worm activity continued for days after. Where did the incident response team fail?
Identifying and scoping an incident during triage is important to successfully handling a security incident. The detection methods used by the team didn't detect all the infected workstations.
Jaime
4 months agoIsabella
4 months agoVerlene
4 months agoLynelle
4 months agoBeatriz
5 months agoDeandrea
5 months agoRenea
5 months agoShala
5 months agoLouisa
5 months agoKanisha
5 months agoPamella
5 months agoTamesha
5 months agoHubert
5 months ago