100-160 · Question #29
Drag and Drop Question Move each NIST Incident Response Lifecycle phase from the list on the left to the correct description on the right. Note: You will receive partial credit for each correct…
The correct answer is Containment, Eradication, and Recovery; Post-Incident Activity; Detection and Analysis; Preparation. NIST Incident Response Lifecycle - Explanation Important context: This drag-and-drop matches phases to descriptions (slots 1–4 on the right), not to a sequential ordering. The actual NIST SP 800-61 lifecycle order is: Preparation → Detection & Analysis →…
Question
Drag and Drop Question Move each NIST Incident Response Lifecycle phase from the list on the left to the correct description on the right. Note: You will receive partial credit for each correct answer. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Containment, Eradication, and Recovery
- Post-Incident Activity
- Detection and Analysis
- Preparation
Explanation
NIST Incident Response Lifecycle - Explanation
Important context: This drag-and-drop matches phases to descriptions (slots 1–4 on the right), not to a sequential ordering. The actual NIST SP 800-61 lifecycle order is: Preparation → Detection & Analysis → Containment/Eradication/Recovery → Post-Incident Activity.
Placement Breakdown
Slot 1 → Containment, Eradication, and Recovery
This slot's description likely covers limiting damage, removing the threat, and restoring systems. CER is the hands-on response phase - you isolate affected systems (containment), remove malware/artifacts (eradication), then bring systems back online (recovery). It's the action phase.
Slot 2 → Post-Incident Activity
This slot's description likely covers lessons learned, documentation, and process improvement. This phase happens after recovery is complete. Teams conduct retrospectives, update runbooks, and file final reports. Common mistake: people think this is optional - NIST treats it as a required lifecycle phase.
Slot 3 → Detection and Analysis
This slot's description likely covers identifying events, validating whether they are incidents, and scoping impact. This is the investigative phase - correlating logs, triaging alerts, and confirming a real incident exists before escalating.
Slot 4 → Preparation
This slot's description likely covers policies, tools, training, and readiness before any incident occurs. Preparation is the first phase chronologically but appears last here because the descriptions are ordered differently than the lifecycle.
Common Misconceptions
| Mistake | Correction |
|---|---|
| Thinking Preparation is least important | It's the foundation - poor preparation makes every other phase harder |
| Confusing Detection with Preparation | Detection happens during an event; Preparation happens before one |
| Skipping Post-Incident Activity | Skipping it means repeating the same mistakes - NIST explicitly requires it |
| Treating CER as one step | It's three distinct sub-phases that can overlap or loop back |
Memory tip: P-D-C-P - Prepare, Detect, Contain/Eradicate/Recover, Post-review.
Topics
Community Discussion
No community discussion yet for this question.
