Ask Question
6 March, 16:20

Scenario: An organization has an incident response plan that requires reporting incidents after verifying them. For security purposes, the organization has not published the plan. Only members of the incident response team know about the plan and its contents. Recently, a server administrator noticed that a web server he manages was running slower than normal. After a quick investigation, he realized an attack was coming from a specific IP address. He immediately rebooted the web server to reset the connection and stop the attack. He then used a utility he found on the Internet to launch a protracted attack against this IP address for several hours. Because attacks from this IP address stopped, he didn't report the incident.

What should have been done before rebooting the web server? A. Review the incidentB. Perform remediation stepsC. Take recovery stepsD. Gather evidence

+2
Answers (1)
  1. 6 March, 18:48
    0
    D, gather evidence, it's obvious he should have reported the problem which as many evidence possibly found, instead decides to reboot the server.
Know the Answer?
Not Sure About the Answer?
Find an answer to your question ✅ “Scenario: An organization has an incident response plan that requires reporting incidents after verifying them. For security purposes, the ...” in 📘 Computers and Technology if you're in doubt about the correctness of the answers or there's no answer, then try to use the smart search and find answers to the similar questions.
Search for Other Answers