Question 1 of 30
Implementation of a new security information and event management (SIEM) system has revealed a high-severity alert indicating potential unauthorized access to a critical database. The security analyst is under pressure to respond immediately to prevent data exfiltration. Which of the following actions represents the most professional and compliant approach to managing this alert?
Initiate a documented incident response playbook procedure that involves correlating the alert with other log sources, assessing the event's context, and performing initial triage to determine the alert's validity and scope before taking containment actions.
Immediately isolate the affected database server from the network to prevent any further potential data loss, without conducting any preliminary investigation.
Mark the alert as a false positive and close the ticket, assuming the SIEM is still undergoing tuning and prone to generating inaccurate alerts.
Escalate the alert directly to a third-party incident response retainer without any internal review or correlation of the event data.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free