Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

A major financial institution's computer incident response team ( CIRT ) is dealing with a complex cyber attack. The attack started with several spear phishing

A major financial institution's computer incident response team (CIRT) is dealing with a complex cyber attack. The attack started with several spear phishing emails sent to crucial employees in different departments. These emails had skillfully crafted messages and appeared to have legitimate attachments. However, upon opening them, the initiation of a highly evasive and previously unknown malware launched. What steps should the CIRT take in the containment phase of the incident response process to address this advanced attack?
a.
Temporarily disable all user accounts and applications to prevent further spread of malware.
b.
Disconnect all affected hosts from the network and shut down all communication channels.
c.
Use network segmentation to isolate and monitor infected systems, to analyze the attackers tactics.
d.
Immediately restore affected systems from backups and apply patches to prevent further attacks.

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access with AI-Powered Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Students also viewed these Databases questions