nerdexam
Cisco

200-201 · Question #172

The SOC team has confirmed a potential indicator of compromise on an endpoint. The team has narrowed the executable file's type to a new trojan family. According to the NIST Computer Security…

The correct answer is D. Prioritize incident handling based on the impact. After detecting and analyzing a potential incident like a new trojan family, the immediate next step according to NIST is to prioritize the incident based on its potential impact.

Submitted by akirajp· Mar 6, 2026Security Policies and Procedures

Question

The SOC team has confirmed a potential indicator of compromise on an endpoint. The team has narrowed the executable file's type to a new trojan family. According to the NIST Computer Security Incident Handling Guide, what is the next step in handling this event?

Options

  • AIsolate the infected endpoint from the network.
  • BPerform forensics analysis on the infected endpoint.
  • CCollect public information on the malware behavior.
  • DPrioritize incident handling based on the impact.

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    9% (4)
  • C
    5% (2)
  • D
    84% (36)

Why each option

After detecting and analyzing a potential incident like a new trojan family, the immediate next step according to NIST is to prioritize the incident based on its potential impact.

AIsolate the infected endpoint from the network.

Isolating the endpoint (containment) is a subsequent step, which should be guided by the incident's prioritization and impact assessment.

BPerform forensics analysis on the infected endpoint.

Performing forensics analysis is an in-depth analytical activity that might happen during or after containment and eradication, often for root cause analysis or evidence collection, but prioritization comes first to guide such efforts.

CCollect public information on the malware behavior.

Collecting public information on malware behavior is part of the analysis phase, which has already begun, but prioritizing the incident's response based on its impact is a more immediate and overarching next decision point.

DPrioritize incident handling based on the impact.Correct

According to NIST SP 800-61, after an incident is detected and initial analysis is performed (confirming IOC, identifying malware type), the next crucial step is to prioritize the incident handling based on its potential impact to determine the appropriate response urgency and resource allocation.

Concept tested: NIST incident response lifecycle - prioritization

Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final

Topics

#NIST incident handling#incident prioritization#IOCs

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice