Cisco Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) 300-215 Question # 30 Topic 4 Discussion

Cisco Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR) 300-215 Question # 30 Topic 4 Discussion

300-215 Exam Topic 4 Question 30 Discussion:
Question #: 30
Topic #: 4

An organization experienced a sophisticated phishing attack that resulted in the compromise of confidential information from thousands of user accounts. The threat actor used a land and expand approach, where initially accessed account was used to spread emails further. The organization's cybersecurity team must conduct an in-depth root cause analysis to uncover the central factor or factors responsible for the success of the phishing attack. The very first victim of the attack was user with email 500236186@test.com. The primary objective is to formulate effective strategies for preventing similar incidents in the future. What should the cybersecurity engineer prioritize in the root cause analysis report to demonstrate the underlying cause of the incident?


A.

investigation into the specific vulnerabilities or weaknesses in the organization's email security systems that were exploited by the attackers


B.

evaluation of the organization's incident response procedures and the performance of the incident response team


C.

examination of the organization's network traffic logs to identify patterns of unusual behavior leading up to the attack


D.

comprehensive analysis of the initial user for presence of an insider who gained monetary value by allowing the attack to happen


Get Premium 300-215 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.