100-160 Question 260
Single answerAn organization experiences a ransomware attack that encrypts critical business data. The incident response team follows the NIST incident response lifecycle to address the issue. During which stage should the team focus on gathering evidence, analyzing the attack, and determining the extent of the compromise?
- A
Preparation
- B
Detection and Analysis
- C
Containment, Eradication, and Recovery
- D
Post-Incident Activity
Show answer and explanation
Correct answer: B
Explanation
In the NIST incident response lifecycle, the Detection and Analysis stage is crucial for identifying an incident, gathering evidence, and determining the impact of the attack. This enables the team to make informed decisions about containment and recovery in subsequent stages.
- A. Incorrect.
The Preparation stage focuses on building policies, training, and tools necessary for incident response but does not involve analyzing or responding to specific incidents.
- B. Correct.
The Detection and Analysis stage involves identifying the incident, gathering evidence, and analyzing the attack to understand its scope and impact. This is the correct stage for the described activities.
- C. Incorrect.
The Containment, Eradication, and Recovery stage involves limiting the damage of the attack, removing the threat, and restoring systems but does not focus on the initial gathering of evidence or analysis.
- D. Incorrect.
The Post-Incident Activity stage focuses on lessons learned and improving future response processes, not on gathering evidence or analyzing the current incident.