100-160 · Question #19
What should an incident response team do immediately after detecting an incident?
The correct answer is D. Notify stakeholders. Notifying stakeholders (D) is the correct immediate action because incident response frameworks (NIST, SANS) require that the right people - leadership, legal, affected parties - be informed as soon as an incident is confirmed, enabling coordinated decision-making and…
Question
What should an incident response team do immediately after detecting an incident?
Options
- AUpdate threat intelligence databases
- BPrepare a final report
- CEradicate the threat
- DNotify stakeholders
How the community answered
(57 responses)- A5% (3)
- B2% (1)
- C2% (1)
- D91% (52)
Explanation
Notifying stakeholders (D) is the correct immediate action because incident response frameworks (NIST, SANS) require that the right people - leadership, legal, affected parties - be informed as soon as an incident is confirmed, enabling coordinated decision-making and compliance with breach notification laws.
- A (Update threat intel) is a post-incident or continuous activity, not an immediate response step.
- C (Eradicate the threat) comes later in the lifecycle - after containment, not immediately after detection. Acting too fast without notification can cause uncoordinated, damaging responses.
- B (Final report) is the last phase of incident response (lessons learned), not the first.
Memory tip: Think of the IR lifecycle acronym PICERL - Preparation → Identification → Containment → Eradication → Recovery → Lessons Learned. Notification of stakeholders happens during the Identification/Containment handoff, long before eradication or reporting.
Topics
Community Discussion
No community discussion yet for this question.