nerdexam
Cisco

200-201 · Question #210

A security analyst notices a sudden surge of incoming traffic and detects unknown packets from unknown senders. After further investigation, the analyst learns that customers claim that they cannot ac

The correct answer is B. detection and analysis. The analyst is actively investigating and detecting an incident by noticing the sudden surge of incoming traffic, identifying unknown packets from unknown senders, and correlating this with customers' complaints about server accessibility issues. This phase involves initial detec

Submitted by fatema_kw· Mar 6, 2026Security Monitoring

Question

A security analyst notices a sudden surge of incoming traffic and detects unknown packets from unknown senders. After further investigation, the analyst learns that customers claim that they cannot access company servers. According to NIST SP800-61, in which phase of the incident response process is the analyst?

Options

  • Apost-incident activity
  • Bdetection and analysis
  • Cpreparation
  • Dcontainment, eradication, and recovery

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    78% (29)
  • C
    5% (2)
  • D
    14% (5)

Explanation

The analyst is actively investigating and detecting an incident by noticing the sudden surge of incoming traffic, identifying unknown packets from unknown senders, and correlating this with customers' complaints about server accessibility issues. This phase involves initial detection, gathering information, and analyzing the situation to understand the nature and scope of the incident before proceeding further with containment, eradication, and recovery efforts.

Topics

#incident response#NIST SP800-61#detection and analysis

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice