🔥 3-day streak
Cisco CCNP Cybersecurity CBRCOR (350-201)101 / 147
Question 101 of 147

A SOC analyst receives an alert that a standard user account suddenly performed actions requiring administrator rights on a Linux server. The team opens the 'Unauthorized Privilege Escalation' playbook, which lists sections titled: Identification Criteria, Data Sources, Analysis Steps, Escalation Path, and Remediation Actions. The analyst has confirmed the alert is a true positive and needs to know which stakeholders to notify and the authority required to isolate the host. Which playbook component should the analyst consult?

Reviewed for accuracy · Report an issueNext question