During routine monitoring, a data analyst observes a surge of suspicious SQL queries from an external address targeting the company's production database that stores customer PII. The organization's incident-response procedure is based on NIST SP 800-61/800-171 guidance. Which action should the analyst take first to satisfy security‐incident reporting requirements and preserve evidence?
Notify the designated incident-response contact immediately with a timestamp, affected system details, and preliminary indicators.
Apply emergency patches to the database server to close the suspected vulnerability before telling anyone.
Shut down the database server and delete temporary files that may contain traces of the attack.
Wait for the forensics team to confirm data exfiltration, then report the event in the next change-control meeting.
Best-practice frameworks such as NIST SP 800-61 and SP 800-171 state that when potential security incidents are detected, the event must be documented and reported through the organization's defined channel before containment or eradication begins. Prompt notification supplies the incident-response team with the information they need to triage, coordinate containment and forensics, and ensures that critical evidence (for example, logs, memory images, or query traces) is not destroyed. Patching a live system, powering it down, or delaying notification until after a full forensic review can compromise evidence or violate required reporting time frames.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-61 and SP 800-171?
Open an interactive chat with Bash
Why is immediate reporting critical during a potential security incident?
Open an interactive chat with Bash
What could happen if the analyst delayed reporting or acted improperly?
Open an interactive chat with Bash
CompTIA Data+ DA0-002 (V2)
Data Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .