Soru

Zorluk: KolayIncident Response Process and Playbooks

Place the core phases of the NIST SP 800-61 Incident Response Lifecycle in the correct sequential order from first to last.

  1. 1Preparation
  2. 2Detection and Analysis
  3. 3Containment, Eradication, and Recovery
  4. 4Post-Incident Activity

Cevap

The correct order of the NIST Incident Response Lifecycle phases is Preparation, Detection and Analysis, Containment, Eradication, and Recovery, and Post-Incident Activity.
The standard NIST SP 800-61 incident response framework follows a logical four-stage lifecycle. It begins with Preparation to establish capabilities, moves to Detection and Analysis to uncover and assess security events, continues to Containment, Eradication, and Recovery to mitigate and recover from the threat, and concludes with Post-Incident Activity to analyze lessons learned.

Adım Adım Çözüm

1
Identify the foundation step required before any attack occurs.
Preparation is established first to equip the team with training and resources.
Without preparation, an organization cannot effectively detect or respond to security threats.
2
Determine the step that follows once operational monitoring begins.
Detection and Analysis comes second to identify security events and validate incidents.
An incident must be detected and analyzed before any mitigation measures can be applied.
3
Identify the active response phase after confirming an incident.
Containment, Eradication, and Recovery takes place third.
Once an incident is identified, responders work to stop threat propagation, eliminate the malware or malicious artifacts, and restore systems.
4
Identify the final phase following system restoration.
Post-Incident Activity concludes the lifecycle.
After operations return to normal, documenting lessons learned ensures continuous improvement of the security posture.

Anahtar Kavram

NIST SP 800-61 Incident Response Lifecycle Phases
Bu soruyu puanla