アナリストは、HR部門のサーバーの1つで低下した処理能力に関するチケットを受け取りました。同じ日に、エンジニアはウイルス対策ソフトウェアが無効になっていることに気づき、いつ、なぜそれが発生したのかを判断できませんでした。 NISTインシデントハンドリングガイドによると、この調査の次の段階は何ですか?
正解:D
According to the NIST Incident Handling Guide, the analysis phase is the next phase of this investigation.
The analysis phase involves examining the evidence and determining the impact, scope, and cause of the incident. The analyst should also identify the attacker's methods, tools, and objectives, as well as any indicators of compromise or malicious activity. The analysis phase may also involve collecting additional data, such as logs, network traffic, or malware samples, to support the investigation. The analysis phase is crucial for developing an effective response and recovery strategy, as well as preventing or mitigating future incidents. References:
* NIST Special Publication 800-61 Revision 2, Computer Security Incident Handling Guide, Section
3.2.4, Analysis (https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf)
* Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS) v1.0, Module 5: Security Incident Response, Lesson 5.2: Incident Response Process, Topic 5.2.3: Analysis Phase (https://learningnetworkstore.cisco.com/on-demand-e-learning/understanding-cisco-cybersecurity-operatio