An incident response team is recommending changes after analyzing a recent compromise in which:
a large number of events and logs were involved;
team members were not able to identify the anomalous behavior and escalate it in a timely manner;
several network systems were affected as a result of the latency in detection;
security engineers were able to mitigate the threat and bring systems back to a stable state; and
the issue reoccurred shortly after and systems became unstable again because the correct information was not gathered during the initial identification phase.
Which two recommendations should be made for improving the incident response process? (Choose two.)
Torie
2 months agoAzzie
9 days agoLeatha
14 days agoMaryann
21 days agoCamellia
1 months agoAndra
2 months agoCecilia
25 days agoJeanice
28 days agoAlyce
1 months agoSabine
2 months agoMila
2 months agoEsteban
24 days agoCamellia
25 days agoHyun
1 months agoVan
1 months agoNickolas
3 months agoVincent
1 months agoAleisha
1 months agoLavina
2 months agoKasandra
3 months agoLezlie
3 months ago