200-201 Question 330
Select 4An organization is developing its incident response plan based on NIST SP 800-61 guidelines. Which of the following are essential elements that should be included in the plan to ensure comprehensive incident response capabilities?
- A
Preparation, including the development of policies and training for incident handlers
- B
Incident detection tools, such as firewalls and antivirus software
- C
Detection and analysis, which involves identifying and prioritizing incidents
- D
Containment, eradication, and recovery procedures to mitigate and resolve incidents
- E
Post-incident activities, such as lessons learned and updating response plans
Show answer and explanation
Correct answers: A, C, D, E
Explanation
NIST SP 800-61 defines the essential elements of an incident response plan as Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activities. These elements ensure a structured and effective approach to managing cybersecurity incidents. Detection tools, while important, are not a core 'element' of the plan itself but rather a resource that supports the incident response process.
- A. Correct.
Correct: Preparation is a critical element of an incident response plan, as emphasized in NIST SP 800-61. It involves establishing policies, procedures, and training to ensure the team is ready to handle incidents.
- B. Incorrect.
Incorrect: While detection tools are important for identifying threats, they are not explicitly listed as an 'element' of an incident response plan in NIST SP 800-61. The plan focuses on processes and activities rather than specific technologies.
- C. Correct.
Correct: Detection and analysis are key components of NIST SP 800-61, which involve identifying and understanding incidents to prioritize the response.
- D. Correct.
Correct: Containment, eradication, and recovery are essential stages in the incident response process, ensuring the incident is mitigated and systems are restored.
- E. Correct.
Correct: Post-incident activities, such as documenting lessons learned and updating response plans, are vital for improving the organization's readiness for future incidents.