Question: Incident response (response to cyber attacks) is handled differently in the cloud. Typically, the SOC will analyze system log data to determine what happened, and
Incident response (response to cyber attacks) is handled differently in the cloud. Typically, the SOC will analyze system log data to determine what happened, and what (whose) resources were affected, perhaps compromised. In SaaS and PaaS, customers have no control over or visibility into system logs. Thus, one important thing a public cloud customer can do to prepare for incidence detection and response is
Group of answer choices
To addresss logging and forensics when writing SLAs with the cloud provider
To run IDS systems at the customer (not the cloud provider) locations
To coordinate with the customer ISP for help in such detection, analysis and response
Contract a 3rd party (not the cloud provider) for forensic help
None of the above
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
