Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27035-Lead-Incident-Manager Exam - Topic 5 Question 7 Discussion

Scenario 1: RoLawyers is a prominent legal firm based in Guadalajara, Mexico. It specializes in a wide range of legal services tailored to meet the diverse needs of its clients. Committed to excellence and integrity, RoLawyers has a reputation for providing legal representation and consultancy to individuals, businesses, and organizations across various sectors.Recognizing the critical importance of information security in today's digital landscape, RoLawyers has embarked on a journey to enhance its information security measures. This company is implementing an information security incident management system aligned with ISO/IEC 27035-1 and ISO/IEC 27035-2 guidelines. This initiative aims to strengthen RoLawyers' protections against possible cyber threats by implementing a structured incident response process to provide guidance on establishing and maintaining a competent incident response team.After transitioning its database from physical to online infrastructure to facilitate seamless information sharing among its branches, RoLawyers encountered a significant security incident. A malicious attack targeted the online database, overloading it with traffic and causing a system crash, making it impossible for employees to access it for several hours.In response to this critical incident, RoLawyers quickly implemented new measures to mitigate the risk of future occurrences. These measures included the deployment of a robust intrusion detection system (IDS) designed to proactively identify and alert the IT security team of potential intrusions or suspicious activities across the network infrastructure. This approach empowers RoLawyers to respond quickly to security threats, minimizing the impact on their operations and ensuring the continuity of its legal services.By being proactive about information security and incident management, RoLawyers shows its dedication to protecting sensitive data, keeping client information confidential, and earning the trust of its stakeholders. Using the latest practices and technologies, RoLawyers stays ahead in legal innovation and is ready to handle cybersecurity threats with resilience and careful attention.According to scenario 1, what information security incident did RoLawyers face?
A) Denial-of-service attack
B) Man-in-the-middle attack
C) Malware attack

PECB ISO-IEC-27035-Lead-Incident-Manager Exam - Topic 5 Question 7 Discussion

Actual exam question for PECB's ISO-IEC-27035-Lead-Incident-Manager exam
Question #: 7
Topic #: 5
[All ISO-IEC-27035-Lead-Incident-Manager Questions]

Scenario 1: RoLawyers is a prominent legal firm based in Guadalajara, Mexico. It specializes in a wide range of legal services tailored to meet the diverse needs of its clients. Committed to excellence and integrity, RoLawyers has a reputation for providing legal representation and consultancy to individuals, businesses, and organizations across various sectors.

Recognizing the critical importance of information security in today's digital landscape, RoLawyers has embarked on a journey to enhance its information security measures. This company is implementing an information security incident management system aligned with ISO/IEC 27035-1 and ISO/IEC 27035-2 guidelines. This initiative aims to strengthen RoLawyers' protections against possible cyber threats by implementing a structured incident response process to provide guidance on establishing and maintaining a competent incident response team.

After transitioning its database from physical to online infrastructure to facilitate seamless information sharing among its branches, RoLawyers encountered a significant security incident. A malicious attack targeted the online database, overloading it with traffic and causing a system crash, making it impossible for employees to access it for several hours.

In response to this critical incident, RoLawyers quickly implemented new measures to mitigate the risk of future occurrences. These measures included the deployment of a robust intrusion detection system (IDS) designed to proactively identify and alert the IT security team of potential intrusions or suspicious activities across the network infrastructure. This approach empowers RoLawyers to respond quickly to security threats, minimizing the impact on their operations and ensuring the continuity of its legal services.

By being proactive about information security and incident management, RoLawyers shows its dedication to protecting sensitive data, keeping client information confidential, and earning the trust of its stakeholders. Using the latest practices and technologies, RoLawyers stays ahead in legal innovation and is ready to handle cybersecurity threats with resilience and careful attention.

According to scenario 1, what information security incident did RoLawyers face?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Bea
7 hours ago
Agreed, Tom. It matches the scenario perfectly.
upvoted 0 times
...
Grover
5 days ago
I think it's A) Denial-of-service attack. The overload of traffic fits.
upvoted 0 times
...
Leonardo
11 days ago
Agreed, but they handled it pretty well with the IDS implementation.
upvoted 0 times
...
Denae
16 days ago
Wow, I didn't expect a firm like RoLawyers to face such a major incident!
upvoted 0 times
...
Julie
2 months ago
Definitely a DDoS attack, they mentioned overload and crash.
upvoted 0 times
...
Kallie
2 months ago
Really? I thought it could be malware.
upvoted 0 times
...
Sherell
2 months ago
Sounds like a classic denial-of-service attack to me.
upvoted 0 times
...
Aleshia
3 months ago
Wait, they just switched to online? That’s risky!
upvoted 0 times
...
Ricarda
3 months ago
Good to see them taking security seriously after that incident.
upvoted 0 times
...
Luis
3 months ago
Definitely a denial-of-service attack. They overloaded the database!
upvoted 0 times
...
Sabine
3 months ago
Really? I thought it might be a malware attack.
upvoted 0 times
...
Malcom
3 months ago
Sounds like a classic denial-of-service attack to me.
upvoted 0 times
...
Marguerita
3 months ago
I feel like this is a trick question. Could it be malware? But the focus on traffic overload really points to a denial-of-service attack, right?
upvoted 0 times
...
Linwood
4 months ago
I was leaning towards a man-in-the-middle attack, but now that I think about it, the traffic overload makes more sense for a denial-of-service.
upvoted 0 times
...
Gianna
4 months ago
I'm not entirely sure, but I remember a practice question about different types of attacks. This one seems like it fits the denial-of-service description.
upvoted 0 times
...
Ira
4 months ago
I think the incident was a denial-of-service attack since it mentioned the database was overloaded with traffic.
upvoted 0 times
...

Save Cancel