nerdexam
Cisco

100-160 · Question #29

Drag and Drop Question Move each NIST Incident Response Lifecycle phase from the list on the left to the correct description on the right. Note: You will receive partial credit for each correct…

The correct answer is Containment, Eradication, and Recovery; Post-Incident Activity; Detection and Analysis; Preparation. NIST Incident Response Lifecycle - Explanation Important context: This drag-and-drop matches phases to descriptions (slots 1–4 on the right), not to a sequential ordering. The actual NIST SP 800-61 lifecycle order is: Preparation → Detection & Analysis →…

Cybersecurity Incident Response

Question

Drag and Drop Question Move each NIST Incident Response Lifecycle phase from the list on the left to the correct description on the right. Note: You will receive partial credit for each correct answer. Answer:

Exhibit

100-160 question #29 exhibit

Answer Area

Drag items

Containment, Eradication, and RecoveryDetection and AnalysisPost-Incident ActivityPreparation

Correct arrangement

  • Containment, Eradication, and Recovery
  • Post-Incident Activity
  • Detection and Analysis
  • Preparation

Explanation

NIST Incident Response Lifecycle - Explanation

Important context: This drag-and-drop matches phases to descriptions (slots 1–4 on the right), not to a sequential ordering. The actual NIST SP 800-61 lifecycle order is: Preparation → Detection & Analysis → Containment/Eradication/Recovery → Post-Incident Activity.


Placement Breakdown

Slot 1 → Containment, Eradication, and Recovery

This slot's description likely covers limiting damage, removing the threat, and restoring systems. CER is the hands-on response phase - you isolate affected systems (containment), remove malware/artifacts (eradication), then bring systems back online (recovery). It's the action phase.

Slot 2 → Post-Incident Activity

This slot's description likely covers lessons learned, documentation, and process improvement. This phase happens after recovery is complete. Teams conduct retrospectives, update runbooks, and file final reports. Common mistake: people think this is optional - NIST treats it as a required lifecycle phase.

Slot 3 → Detection and Analysis

This slot's description likely covers identifying events, validating whether they are incidents, and scoping impact. This is the investigative phase - correlating logs, triaging alerts, and confirming a real incident exists before escalating.

Slot 4 → Preparation

This slot's description likely covers policies, tools, training, and readiness before any incident occurs. Preparation is the first phase chronologically but appears last here because the descriptions are ordered differently than the lifecycle.


Common Misconceptions

MistakeCorrection
Thinking Preparation is least importantIt's the foundation - poor preparation makes every other phase harder
Confusing Detection with PreparationDetection happens during an event; Preparation happens before one
Skipping Post-Incident ActivitySkipping it means repeating the same mistakes - NIST explicitly requires it
Treating CER as one stepIt's three distinct sub-phases that can overlap or loop back

Memory tip: P-D-C-P - Prepare, Detect, Contain/Eradicate/Recover, Post-review.

Topics

#NIST incident response#IR lifecycle#preparation#containment

Community Discussion

No community discussion yet for this question.

Full 100-160 Practice