Question 1 of 30
Upon reviewing a critical security incident involving a suspected data breach, a security operations team is faced with a dilemma: the affected systems are crucial for ongoing business operations, and there is immense pressure to restore services immediately. However, the nature of the incident suggests that forensic evidence may be present and vital for understanding the attack vector and preventing recurrence. Which of the following approaches best balances the need for operational continuity with the imperative for thorough investigation and legal compliance?
Immediately isolate the affected systems, initiate a forensic data acquisition process to preserve evidence, and then proceed with containment and eradication strategies before full restoration, ensuring all actions are meticulously documented.
Prioritize the immediate restoration of affected systems to minimize business disruption, assuming that logs and system states will remain sufficiently intact for a later, less urgent forensic analysis.
Grant a third-party forensic consultant immediate and unrestricted access to all potentially affected systems and user data to expedite the investigation, with minimal oversight to avoid delaying their work.
Focus on patching known vulnerabilities and implementing basic security controls to prevent further intrusion, while deferring detailed forensic analysis and evidence preservation until after all systems are confirmed to be operational.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free