Reference no: EM133958070
Assignment:
Detection and Containment Processes
1. What is a CoA matrix?
2. Which class of data criticality factor has been omitted from the following list? PII, PHI, SPI, IP, financial and corporate information.
3. You are explaining containment techniques to a junior analyst. What distinction can you make between isolation-based and segmentation-based containment?
4. Your SIEM has alerted you to ongoing scanning activity directed against workstations and servers. The host intrusion detection on each target has blocked access to the source IP automatically. What are your options and considerations for investigating this incident?
5. Which class of data criticality factor has been omitted from the following list? PII, PHI, SPI, IP, financial and corporate information.
6. Which class of data criticality factor has been omitted from the following list? PII, PHI, SPI, IP, financial and corporate information.
7. A technician attending a user who has been complaining about frequent lockups and log-offs with his machine has discovered a large cache of encrypted zipped files stored within the "System Volume Information" folder. What are your priorities for incident response and what tools will you use?