ExamGecko
Question list
Search
Search

Related questions











Question 280 - 200-201 discussion

Report
Export

An engineer is working on a ticket for an incident from the incident management team A week ago. an external web application was targeted by a DDoS attack Server resources were exhausted and after two hours it crashed. An engineer was able to identify the attacker and technique used Three hours after the attack, the server was restored and the engineer recommended implementing mitigation by Blackhole filtering and transferred the incident ticket back to the IR team According to NIST SP800-61, at which phase of the incident response did the engineer finish work?

A.

preparation

Answers
A.

preparation

B.

post-incident activity

Answers
B.

post-incident activity

C.

containment eradication and recovery

Answers
C.

containment eradication and recovery

D.

detection and analysis

Answers
D.

detection and analysis

Suggested answer: C

Explanation:

According to NIST SP800-61, the incident response phase called ''Containment, Eradication, and Recovery'' involves containing the incident, eradicating the threat, and recovering from the incident2. In the scenario described, the engineer worked on containing the DDoS attack by identifying the attacker and the technique used, which is part of the containment process. The recommendation to implement Blackhole filtering is part of the eradication process, where measures are taken to prevent the attack from happening again. Finally, restoring the server is part of the recovery process, where normal operations are resumed.Therefore, the engineer finished work during the ''Containment, Eradication, and Recovery'' phase.Reference:: NIST SP800-61 Computer Security Incident Handling Guide2.

asked 07/10/2024
Brian Charlton,
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first