200-201 Question 333
Select 2During a cybersecurity incident, your team observes unusual outbound traffic from multiple systems in the network. According to the NIST.SP800-61 framework, which steps of the incident analysis process should you prioritize to map this observation effectively?
- A
Identification of indicators to understand the scope of the incident
- B
Containment of affected systems to prevent further impact
- C
Validation of the incident by analyzing logs and system behavior
- D
Eradication of the malicious software from the affected systems
- E
Documentation of the findings for future reference and lessons learned
Show answer and explanation
Correct answers: A, C
Explanation
The analysis process based on NIST.SP800-61 involves identifying indicators and validating the incident to confirm its authenticity and scope. These steps are crucial in understanding the nature of the threat before moving to containment, eradication, or other phases of incident handling.
- A. Correct.
Identification of indicators is critical as it helps determine what evidence to look for and understand the extent of the incident.
- B. Incorrect.
Containment is necessary but is part of the response phase, not the analysis process, as per NIST.SP800-61.
- C. Correct.
Validation involves confirming whether the observed activity is indeed malicious, which is a key part of the analysis process.
- D. Incorrect.
Eradication is part of the recovery process and occurs after analysis has been conducted.
- E. Incorrect.
Documentation is important but is part of the post-incident handling phase, not the analysis phase.