100-160 Question 261
Single answerYour organization has recently experienced a malware attack that compromised several endpoints. As part of the incident response process, the cybersecurity team is currently documenting lessons learned and creating recommendations to avoid similar incidents in the future. Which stage of the NIST incident response lifecycle does this activity belong to?
- A
Preparation
- B
Detection and Analysis
- C
Containment, Eradication, and Recovery
- D
Post-Incident Activity
Show answer and explanation
Correct answer: D
Explanation
The NIST incident response lifecycle includes four stages: Preparation, Detection and Analysis, Containment, Eradication, and Recovery, and Post-Incident Activity. Documenting lessons learned and creating recommendations for future improvements is a critical part of the Post-Incident Activity stage, as it allows organizations to refine their incident response processes and strengthen defenses based on real-world incidents.
- A. Incorrect.
Preparation involves creating policies, plans, and procedures to handle future incidents, but it does not include documenting lessons learned from a specific incident.
- B. Incorrect.
Detection and Analysis focuses on identifying and analyzing an incident but does not deal with post-incident documentation or recommendations.
- C. Incorrect.
Containment, Eradication, and Recovery involves actively mitigating the impact of an incident, removing threats, and restoring systems, but it does not include reviewing the incident after it is resolved.
- D. Correct.
Post-Incident Activity includes documenting lessons learned, analyzing the incident, and making recommendations to improve the response process and prevent future incidents, which aligns with the scenario.