Question 1 of 30
The assessment process reveals a sophisticated phishing campaign has successfully compromised several executive email accounts, potentially exposing sensitive corporate strategy documents. The Incident Response Team (IRT) is activated. Which of the following actions best aligns with regulatory compliance and professional incident response best practices in this scenario?
Immediately initiate containment procedures to isolate compromised accounts and systems, meticulously document all actions taken, and preserve all relevant logs and digital evidence in a forensically sound manner, while simultaneously engaging legal counsel to prepare for potential breach notification obligations.
Prioritize public relations efforts to craft a carefully worded statement for external stakeholders, downplaying the severity of the incident until the full scope is understood, and begin immediate system restoration to minimize service disruption.
Focus solely on eradicating the threat by wiping and rebuilding affected systems without preserving any logs or forensic data, as the primary goal is to restore normal operations as quickly as possible.
Delay internal notification to the legal department and compliance officers until the initial containment and eradication phases are fully completed to avoid overwhelming them with preliminary, unverified information.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free