ExamGecko
Question list
Search
Search

Related questions











Question 77 - 200-201 discussion

Report
Export

A security analyst notices a sudden surge of incoming traffic and detects unknown packets from unknown senders After further investigation, the analyst learns that customers claim that they cannot access company servers According to NIST SP800-61, in which phase of the incident response process is the analyst?

A.

post-incident activity

Answers
A.

post-incident activity

B.

detection and analysis

Answers
B.

detection and analysis

C.

preparation

Answers
C.

preparation

D.

containment, eradication, and recovery

Answers
D.

containment, eradication, and recovery

Suggested answer: B

Explanation:

The analyst is in the detection and analysis phase of the incident response process according to NIST SP800-61. In this phase, events are detected and analyzed to determine whether they constitute incidents that require a response. It involves monitoring security events or data collection, correlation, and analysis of log entries and network flow data, among others. The goal is to identify incidents quickly so that appropriate actions can be taken.Reference:= NIST SP800-61, Computer Security Incident Handling Guide, Section 3.2: Detection and Analysis

asked 07/10/2024
EDUARDO LEE
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first