200-201 Question 334
Select 2During a cybersecurity incident at a financial institution, the security operations team is tasked with mitigating the attack and preventing further damage. The team identifies and isolates the affected systems, gathers evidence of the attack, and develops a plan to prevent recurrence. Based on the NIST.SP800-61 framework, which steps of the incident response process do these actions correspond to?
- A
Containment, eradication, and recovery
- B
Preparation
- C
Detection and analysis
- D
Post-incident activity
- E
Risk assessment
Show answer and explanation
Correct answers: A, D
Explanation
The described actions align with the containment, eradication, and recovery phase, where the incident is mitigated and systems are restored, as well as the post-incident activity phase, where evidence is gathered and lessons are learned to improve future responses. These are key steps in the NIST.SP800-61 incident response framework.
- A. Correct.
Correct: Containment, eradication, and recovery involve isolating affected systems, mitigating the attack, and restoring normal operations, which matches the actions described in the scenario.
- B. Incorrect.
Incorrect: Preparation involves steps taken before an incident occurs, such as creating incident response plans and training, which are not described in this scenario.
- C. Incorrect.
Incorrect: Detection and analysis involve identifying and confirming the occurrence of an incident, which happens before the described actions in the scenario.
- D. Correct.
Correct: Post-incident activity includes gathering evidence and developing lessons learned to prevent future incidents, aligning with the described actions.
- E. Incorrect.
Incorrect: Risk assessment involves evaluating vulnerabilities and risks to an organization, which is not part of the described scenario.