100-160 Question 263
Select 2Your organization recently experienced a ransomware attack, and you have been asked to assist in the incident response process. According to the NIST Special Publication 800-61, which of the following tasks should be prioritized during the 'Containment, Eradication, and Recovery' stage of the incident response lifecycle?
- A
Isolating affected systems to prevent further spread of the ransomware
- B
Identifying the type of ransomware used by analyzing the malware sample
- C
Developing a communications plan to inform stakeholders about the incident
- D
Restoring systems from clean backups and verifying their integrity
- E
Monitoring network traffic for potential indicators of compromise (IOCs)
Show answer and explanation
Correct answers: A, D
Explanation
The 'Containment, Eradication, and Recovery' stage of the NIST incident response lifecycle focuses on isolating affected systems to limit the damage, removing the threat, and restoring normal operations. Tasks like isolating systems and restoring from backups are critical in this phase, while activities like malware analysis or traffic monitoring belong to earlier stages.
- A. Correct.
Isolating affected systems is critical during the containment phase to prevent further spread of the ransomware, aligning with the goals of this stage in the incident response lifecycle.
- B. Incorrect.
Analyzing the malware sample is part of the identification phase, not the containment, eradication, and recovery stage.
- C. Incorrect.
Developing a communications plan is associated with the preparation phase, not this specific stage of the incident response lifecycle.
- D. Correct.
Restoring systems from clean backups is a key task in the recovery phase, ensuring systems are operational and free from compromise.
- E. Incorrect.
Monitoring network traffic for IOCs is generally part of the identification and detection phase, not the containment, eradication, and recovery stage.