Question: The EC-Council Certified Incident Handler (ECIH) at an organization suspects an employee to be an insider threat due to unusual network activities. The handler is

The EC-Council Certified Incident Handler (ECIH) at an organization suspects an employee to be an insider threat due to unusual network activities. The handler is currently using the ActivTrak Employee Monitoring Solution for insider threat detection. Which of the following actions is the most appropriate first step for the incident handler to perform in this scenario?

A. Contact law enforcement agencies and legal authorities for a thorough investigation.

B. Analyzing the screenshots captured by ActivTrak and the resources involved in the suspected activities.

C. Blocking all access for the suspected employee, including email, application accounts, physical access cards, and network credentials.

D. Immediately report the suspicious activity to senior management to seek further advice

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock