ある組織が最近、ランサムウェア攻撃を受けました。セキュリティ チームのリーダーは、攻撃の再発を懸念しています。ただし、それ以上のセキュリティ対策は実装されていません。
次のプロセスのうち、潜在的な防止の推奨事項を特定するために使用できるものはどれですか?
正解:C
Preparation is the process that can be used to identify potential prevention recommendations after a security incident, such as a ransomware attack. Preparation involves planning and implementing security measures to prevent or mitigate future incidents, such as by updatingpolicies, procedures, or controls, conducting training or awareness campaigns, or acquiring new tools or resources. Detection is the process of discovering or identifying security incidents, not preventing them. Remediation is the process of containing or resolving security incidents, not preventing them. Recovery is the process of restoring normal operations after security incidents, not preventing them. Verified References:
https://www.comptia.org/blog/what-is-incident-responsehttps://partners.comptia.org/docs/default-source/resourc