Performing CyberOps Using Cisco Security Technologies (CBRCOR) — Question 108

Engineers are working to document, list, and discover all used applications within an organization. During the regular assessment of applications from the HR backup server, an engineer discovered an unknown application. The analysis showed that the application is communicating with external addresses on a non- secure, unencrypted channel. Information gathering revealed that the unknown application does not have an owner and is not being used by a business unit. What are the next two steps the engineers should take in this investigation? (Choose two.)

Answer options

Correct answer: A, D

Explanation

The correct answers are A and D. Option A is essential as it involves understanding the data involved and engaging the incident response team, which is critical for security. Option D is also correct as it seeks to clarify ownership and usage of the application, which is vital for accountability. Options B and C do not address the immediate need to secure data and identify ownership effectively.