Question 1
Statement: A cyberattack has breached the servers of a major bank, compromising customer data. The attack is ongoing.
Course of Action (Actions must be sequenced in order of priority):
I. Isolate affected servers to prevent further data exfiltration.
II. Notify affected customers and regulatory authorities about the breach.
III. Initiate forensic investigation to determine the scope and method of attack.
IV. Implement immediate security patches and firewall rule changes.
V. Engage cybersecurity experts for long-term security architecture review.
Priority Sequence: Containment (I) → Patching (IV) → Investigation (III) → Notification (II) → Long-term Review (V). Stop the attack first, then fix vulnerabilities, then investigate, then notify.