Soru

Zorluk: KolayIncident Response Process and Playbooks

An organization is updating its cybersecurity incident response plan according to the standard NIST SP 800-61 framework. In what sequential order should the core phases of the incident response lifecycle be performed from first to last?

  1. 1Preparation
  2. 2Detection and Analysis
  3. 3Containment, Eradication, and Recovery
  4. 4Post-Incident Activity

Cevap

The correct sequential order of the NIST incident response lifecycle phases is Preparation, followed by Detection and Analysis, then Containment, Eradication, and Recovery, and finally Post-Incident Activity.
According to NIST SP 800-61, the standard incident response process follows four sequential phases: Preparation (setting up response tools, policies, and training), Detection and Analysis (identifying security events and determining their scope), Containment, Eradication, and Recovery (limiting impact, purging threat actors or artifacts, and restoring systems), and Post-Incident Activity (conducting lessons-learned analysis to improve future readiness).

Adım Adım Çözüm

1
Identify the foundational phase established prior to security incidents.
Preparation is the initial phase.
An incident response team must prepare infrastructure, tools, and playbooks before attacks occur.
2
Identify the phase triggered by suspicious activity or system alerts.
Detection and Analysis follows Preparation.
Security operations teams must detect anomalies, validate security events, and analyze threat vectors.
3
Identify the phase dedicated to stopping the threat and restoring operational baselines.
Containment, Eradication, and Recovery follows Detection and Analysis.
Once an incident is confirmed and analyzed, responders must limit its spread, clean infected hosts, and bring systems back online securely.
4
Identify the concluding evaluation phase after threat resolution.
Post-Incident Activity is the final phase.
After the incident is mitigated and operations are restored, the team holds lessons-learned meetings to update playbooks and improve future response.

Anahtar Kavram

NIST Incident Response Lifecycle Phases
Bu soruyu puanla