Study. uk . com
  1. Home
  2. All questions
  3. Question 66

CISSP study material · question 66 of 500

During an intrusion, an analyst proposes leaving the attacker's access in place and steering the session into an instrumented sandbox to observe their techniques before the incident is shut down. Which action should the incident commander take before that diversion begins?

  1. Extend log retention so that the telemetry captured in the sandbox can be archived
  2. Obtain a review from the organisation's legal counsel covering the proposed diversion
  3. Confirm with the vendor that the sandbox reproduces the production configuration faithfully
  4. Notify the affected business unit's service desk that users may see degraded performance
Show the answer

Answer: B. Obtain a review from the organisation's legal counsel covering the proposed diversion

Watching a diverted attacker postpones shutting the incident down and lets them deepen privileges or reach untouched systems, so legal counsel reviews it first; sandbox fidelity and retention are secondary.

Source: NIST SP 800-61 Rev. 3 (NIST) — SP 800-61r3 > Section 3.2, RS.MI (Incident Mitigation)

Challenge yourself on this topic → Study as cards