Which of the following is NOT a typical step in a security incident workflow in FOSSE?

Enhance your skills for the Front Office System Support Environment certification. Test your knowledge with a series of multiple-choice questions, detailed hints, and explanations. Be fully prepared for the FOSSE exam!

Multiple Choice

Which of the following is NOT a typical step in a security incident workflow in FOSSE?

Explanation:
In a security incident workflow the steps are focused on reacting to and learning from incidents: detect the issue, contain it to limit damage, and then move into recovery and a post-incident review to capture lessons and improve defenses. Threat hunting, on the other hand, is a proactive, ongoing activity that looks for signs of attacker activity across the environment. It isn’t a defined, standard step within the incident response lifecycle; it operates outside the formal incident-handling sequence to improve detection and prevention in general. So threat hunting is not a typical step in the security incident workflow, making it the best choice.

In a security incident workflow the steps are focused on reacting to and learning from incidents: detect the issue, contain it to limit damage, and then move into recovery and a post-incident review to capture lessons and improve defenses. Threat hunting, on the other hand, is a proactive, ongoing activity that looks for signs of attacker activity across the environment. It isn’t a defined, standard step within the incident response lifecycle; it operates outside the formal incident-handling sequence to improve detection and prevention in general. So threat hunting is not a typical step in the security incident workflow, making it the best choice.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy