Scenario You are working as a cybersecurity analyst at FinSecure Corp, a midsize financial organization. A recent malware incident has prompted a comprehensive review of the company’s incident response procedures and network security architecture. FinSecure operates primarily in an on-premises environment with some remote users connecting via VPN. As part of this review, you have been asked to evaluate how the incident was handled, assess the network architecture for vulnerabilities, and recommend adjustments to firewall and intrusion detection system (IDS) configurations to prevent future threats.
Refer to the attached “Incident and Network Security Artifacts” in the Supporting Documents section.
Requirements
A. Evaluate the organization’s response to the security incident by doing the following:
1. Identify three actions the organization took in response to the incident.
2. Evaluate the effectiveness of each of the three actions from part A1 using a recognized incident response framework (e.g., NIST, SANS, ISO).
3. Recommend two improvements to the organization’s incident response procedure that would strengthen detection, containment, or recovery efforts in future incidents, and justify why each recommendation would improve the organization’s incident response effectiveness.
B. Analyze the provided network architecture diagram and firewall configuration by doing the following:
1. Identify three vulnerabilities, design




Reviews
There are no reviews yet.