CISM Certified Information Security Manager – Question1433

For an organization that provides web-based services, which of the following security events would MOST likely initiate an incident response plan and be escalated to management?

A.
Multiple failed login attempts on an employee’s workstation
B. Suspicious network traffic originating from the demilitarized zone (DMZ)
C. Several port scans of the web server
D. Anti-malware alerts on several employees’ workstations

Correct Answer: B