Question: Brainstorm an incident response process that can be fully or partially automated. Explain the process, including the type of data that needs to be collected
Brainstorm an incident response process that can be fully or partially automated. Explain the process, including the type of data that needs to be collected (threat intelligence, logs, etc.) and actions that need to be done (put in a ticket, delete email, quarantine system, etc.). For example, you might want to automate the response to a phishing email being opened or a reported malware infection.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
