112-52 · Question #157
What is the first phase in the incident response lifecycle?
The correct answer is D. Preparation. Preparation (D) is the first phase because no effective incident response can occur without it - this phase involves establishing policies, building response teams, acquiring tools, and training staff before any incident occurs. Without preparation, organizations lack the foundat
Question
What is the first phase in the incident response lifecycle?
Options
- AContainment
- BEradication
- CIdentification
- DPreparation
How the community answered
(30 responses)- A7% (2)
- C3% (1)
- D90% (27)
Explanation
Preparation (D) is the first phase because no effective incident response can occur without it - this phase involves establishing policies, building response teams, acquiring tools, and training staff before any incident occurs. Without preparation, organizations lack the foundation to respond effectively.
- Containment (A) comes after an incident has already been detected and analyzed - you can't contain something you haven't identified yet.
- Eradication (B) is even later in the lifecycle, focused on removing the threat after it has been contained.
- Identification/Detection (C) is the second phase, where you determine whether an event qualifies as an incident - it logically follows preparation.
Memory tip: Use the acronym PICERL - Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned - to recall the full NIST incident response lifecycle in order. Since "P" comes first, Preparation is always your anchor.
Topics
Community Discussion
No community discussion yet for this question.