The correct answer is B because the next step after receiving an alert is to analyze and validate the event to determine whether it is a true incident, a false positive, or benign activity. Incident response should follow a structured process: detection, validation, classification, prioritization, containment, eradication, recovery, and lessons learned. Reinstalling the operating system is premature and may destroy evidence needed for analysis. Requesting an IP address block may be appropriate later if the external server is confirmed to be malicious, but blocking without validation can disrupt legitimate business communication. Isolating the workstation may become necessary if compromise is confirmed or strongly suspected, but the question asks what should be done next after an alert. CISM incident management principles require events to be validated before full incident response actions are taken. Proper analysis ensures that response actions are proportionate, evidence is preserved, and business disruption is minimized. Therefore, analyzing and validating the event is the best next step.
[Reference: CISM Information Security Incident Management; event validation, incident identification, analysis, classification, and response process principles., , ]
Submit