Soru

Zorluk: KolayIncident Response Process and Playbooks

An organization is aligning its cybersecurity procedures with the NIST SP 800-61 incident response framework. Place the core phases of the incident response process in the correct chronological order from first to last.

  1. 1Preparation
  2. 2Detection and Analysis
  3. 3Containment, Eradication, and Recovery
  4. 4Post-Incident Activity

Cevap

The correct chronological sequence of the incident response lifecycle is Preparation, followed by Detection and Analysis, then Containment, Eradication, and Recovery, and ending with Post-Incident Activity.
According to the NIST SP 800-61 framework, the incident response lifecycle progresses through four major phases: Preparation (setting up tools, policies, and teams), Detection and Analysis (identifying and investigating security events), Containment, Eradication, and Recovery (limiting impact, eliminating the threat, and restoring operations), and Post-Incident Activity (conducting lessons learned to refine future response).

Adım Adım Çözüm

1
Identify the foundational phase established prior to active incidents.
Preparation is identified as the first phase.
Security teams must develop playbooks, configure monitoring tools, and establish communication plans before a security event occurs.
2
Determine the phase initiated when anomalous activity or security alerts are reported.
Detection and Analysis is identified as the second phase.
Analysts must evaluate alerts, scope the impact, and validate whether an active breach or compromise is taking place.
3
Identify the active response and mitigation actions taken after confirmation of an incident.
Containment, Eradication, and Recovery is identified as the third phase.
Responders must limit damage by containing affected systems, eliminate root causes/malware, and securely restore services.
4
Determine the final phase following complete system restoration.
Post-Incident Activity is identified as the fourth phase.
Conducting lessons-learned analysis and updating documentation ensures continuous improvement of the organization's security posture.

Anahtar Kavram

NIST SP 800-61 Incident Response Lifecycle Phases
Bu soruyu puanla