ExamGecko
Question list
Search
Search

Related questions











Question 329 - 200-201 discussion

Report
Export

A member of the SOC team is checking the dashboard provided by the Cisco Firepower Manager for further Isolation actions. According to NIST SP800-61, in which phase of incident response is this action?

A.

Cost-incident activity phase

Answers
A.

Cost-incident activity phase

B.

Preparation phase

Answers
B.

Preparation phase

C.

Selection and analyze phase

Answers
C.

Selection and analyze phase

D.

The radiation and recovery phase

Answers
D.

The radiation and recovery phase

Suggested answer: D

Explanation:

According to NIST SP800-61, the incident response lifecycle consists of four phases: Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity.

When a SOC team member checks the Cisco Firepower Manager dashboard for further isolation actions, they are working within the Eradication and Recovery phase.

This phase focuses on removing the threat from the environment and recovering affected systems to normal operations.

NIST SP800-61 Computer Security Incident Handling Guide

Incident Response Phases Explained

Role of SOC in Incident Response

asked 07/10/2024
Budi Gunawan
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first