Question 1 of 30
In a cybersecurity incident involving a suspected insider threat, a forensic analyst is tasked with conducting behavioral analysis on user activity logs. The analyst observes that a particular employee has accessed sensitive files outside of normal working hours and has transferred large amounts of data to an external USB device. Which of the following actions should the analyst prioritize to effectively assess the situation and mitigate potential risks?
Correlate the user's access patterns with historical data to identify anomalies and establish a baseline of normal behavior.
Immediately revoke the employee's access to all systems to prevent further data exfiltration.
Conduct a physical search of the employee's workspace to find any unauthorized devices.
Notify law enforcement about the suspected data breach without further investigation.

Preparing for CISCO 300-215 Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free