I practiced a question similar to this, and I feel like disconnecting network communications (D) could be part of the containment phase instead of identification.
This is a tricky one, but I think I've got it. The Identification phase is all about gathering information and confirming the incident, so option C seems like the best choice. I'm feeling pretty confident about this one.
I'm a bit confused here. Isn't the Identification phase more about verifying the root cause and applying security patches? I'm not sure if option C is the right answer, but I could be wrong. Guess I'll have to think this through a bit more.
Okay, I've got this. The Identification phase is all about confirming that an incident has actually occurred and gathering the necessary data to understand what's going on. So I'd say option C is the way to go.
Hmm, I'm a little unsure about this one. I know the Identification phase is all about gathering information, but I'm not sure if option C is the best choice. Maybe I should review my notes on incident response again.
Sabine
25 days agoGracie
30 days agoWillow
1 month agoMattie
1 month agoJame
2 months agoGussie
2 months agoIvan
2 months agoTasia
2 months agoLucia
2 months agoAlpha
2 months agoRyan
3 months agoSue
3 months agoCurt
3 months agoRaul
4 months agoWendell
4 months agoNelida
4 months agoAllene
4 months agoAllene
4 months agoLorrie
4 months agoMarjory
5 months agoLuis
5 months agoBarney
5 months agoFelton
5 months agoTrinidad
19 days ago