問題文
A SOC is deciding which adaptive response actions to attach to a detection for a suspected compromised endpoint. Which choices are appropriate to run automatically on every match? (Select two.)
選択肢
- Isolating the host from the network, because that stops the adversary without destroying evidence.
- Gathering additional context about the asset and the account involved, because collecting information does not change the environment.
- Deleting the file identified by the detection, because removing it prevents reinfection.
- Disabling the user account, because acting immediately is what limits the damage and the cost of a wrongly disabled account is lower than the cost of a compromise that spreads while the team is still deciding what to do.
- Creating a record in the ticketing system so the work is tracked, because a superfluous ticket can be closed at low cost.