200-201 · Question #210
A security analyst notices a sudden surge of incoming traffic and detects unknown packets from unknown senders. After further investigation, the analyst learns that customers claim that they cannot ac
The correct answer is B. detection and analysis. The analyst is actively investigating and detecting an incident by noticing the sudden surge of incoming traffic, identifying unknown packets from unknown senders, and correlating this with customers' complaints about server accessibility issues. This phase involves initial detec
Question
A security analyst notices a sudden surge of incoming traffic and detects unknown packets from unknown senders. After further investigation, the analyst learns that customers claim that they cannot access company servers. According to NIST SP800-61, in which phase of the incident response process is the analyst?
Options
- Apost-incident activity
- Bdetection and analysis
- Cpreparation
- Dcontainment, eradication, and recovery
How the community answered
(37 responses)- A3% (1)
- B78% (29)
- C5% (2)
- D14% (5)
Explanation
The analyst is actively investigating and detecting an incident by noticing the sudden surge of incoming traffic, identifying unknown packets from unknown senders, and correlating this with customers' complaints about server accessibility issues. This phase involves initial detection, gathering information, and analyzing the situation to understand the nature and scope of the incident before proceeding further with containment, eradication, and recovery efforts.
Topics
Community Discussion
No community discussion yet for this question.