I practiced a question similar to this, and I feel like disconnecting network communications (D) could be part of the containment phase instead of identification.
This is a tricky one, but I think I've got it. The Identification phase is all about gathering information and confirming the incident, so option C seems like the best choice. I'm feeling pretty confident about this one.
I'm a bit confused here. Isn't the Identification phase more about verifying the root cause and applying security patches? I'm not sure if option C is the right answer, but I could be wrong. Guess I'll have to think this through a bit more.
Okay, I've got this. The Identification phase is all about confirming that an incident has actually occurred and gathering the necessary data to understand what's going on. So I'd say option C is the way to go.
Hmm, I'm a little unsure about this one. I know the Identification phase is all about gathering information, but I'm not sure if option C is the best choice. Maybe I should review my notes on incident response again.
Sue
3 days agoCurt
8 days agoRaul
13 days agoWendell
18 days agoNelida
24 days agoAllene
29 days agoAllene
1 month agoLorrie
1 month agoMarjory
1 month agoLuis
2 months agoBarney
2 months agoFelton
2 months ago