ISC Certified Information Systems Security Professional (CISSP) CISSP Question # 194 Topic 20 Discussion

ISC Certified Information Systems Security Professional (CISSP) CISSP Question # 194 Topic 20 Discussion

CISSP Exam Topic 20 Question 194 Discussion:
Question #: 194
Topic #: 20

A security analyst for a large financial institution is reviewing network traffic related to an incident. The analyst determines the traffic is irrelevant to the investigation but in the process of the review, the analyst also finds that an applications data, which included full credit card cardholder data, is transferred in clear text between the server and user’s desktop. The analyst knows this violates the Payment Card Industry Data Security Standard (PCI-DSS). Which of the following is the analyst’s next step?


A.

Send the log file co-workers for peer review


B.

Include the full network traffic logs in the incident report


C.

Follow organizational processes to alert the proper teams to address the issue.


D.

Ignore data as it is outside the scope of the investigation and the analyst’s role.


Get Premium CISSP Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.