Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) Free Practice Test — 30 Questions

Exam Code: CBRFIR

30 questions · Full explanations · No account required

Free
Question 1 of 30

Anya, the incident response lead, is coordinating her team\'s efforts against a multi-stage phishing attack that has successfully exfiltrated sensitive customer data and escalated privileges within the network. The attackers have established persistence on several critical servers. Considering the immediate need to halt further damage and preserve evidence, which of the following actions represents the most critical *initial* step in the incident response lifecycle for this scenario, balancing containment with the preservation of forensic integrity?

Immediately isolate all identified compromised systems from the network to prevent lateral movement and further data exfiltration.
Initiate the mandatory breach notification process as required by the California Consumer Privacy Act (CCPA) and notify all affected customers.
Deploy enhanced endpoint detection and response (EDR) agents across the entire network to detect and block any remaining malicious activity.
Commence full forensic disk imaging of all systems exhibiting suspicious activity, prioritizing volatile data collection from active memory.

About the Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) Certification

These free practice questions are designed to help you assess your readiness for the Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.