Bird
0
0

During the detection and analysis phase, a security analyst receives an alert about unusual login attempts. What should be the analyst's immediate next step?

medium🚀 Application Q13 of 15
Cybersecurity - Incident Response
During the detection and analysis phase, a security analyst receives an alert about unusual login attempts. What should be the analyst's immediate next step?
AIgnore the alert if it happens outside business hours
BImmediately block all user accounts
CAnalyze the alert data to confirm if it is a real threat
DRestart the server to clear alerts
Step-by-Step Solution
Solution:
  1. Step 1: Understand alert handling in detection phase

    The analyst must analyze alert data to verify if the alert indicates a real threat.
  2. Step 2: Evaluate other options for appropriateness

    Ignoring alerts or drastic actions like blocking all accounts or restarting servers are not proper immediate responses.
  3. Final Answer:

    Analyze the alert data to confirm if it is a real threat -> Option C
  4. Quick Check:

    Alert response = analyze data first [OK]
Quick Trick: Always verify alerts before acting [OK]
Common Mistakes:
MISTAKES
  • Ignoring alerts based on time
  • Taking drastic actions without analysis
  • Restarting servers unnecessarily

Want More Practice?

15+ quiz questions · All difficulty levels · Free

Free Signup - Practice All Questions
More Cybersecurity Quizzes