200-201 · Question #272
Which two elements of the incident response process are stated in NIST SP 800-61 r2? (Choose two.)
The correct answer is A. detection and analysis B. post-incident activity. NIST SP 800-61 Rev. 2 outlines the Incident Response Lifecycle, which includes distinct phases for actively identifying and analyzing security incidents, as well as conducting crucial follow-up activities.
Question
Which two elements of the incident response process are stated in NIST SP 800-61 r2? (Choose two.)
Options
- Adetection and analysis
- Bpost-incident activity
- Cvulnerability scoring
- Dvulnerability management
- Erisk assessment
How the community answered
(20 responses)- A90% (18)
- C5% (1)
- D5% (1)
Why each option
NIST SP 800-61 Rev. 2 outlines the Incident Response Lifecycle, which includes distinct phases for actively identifying and analyzing security incidents, as well as conducting crucial follow-up activities.
'Detection and Analysis' is a core phase in the NIST incident response lifecycle, focusing on identifying security events, determining if they are incidents, and analyzing their scope and nature.
'Post-Incident Activity' is the final phase of the NIST incident response process, involving lessons learned, evidence retention, and using findings to improve future incident handling and overall security posture.
Vulnerability scoring is typically part of vulnerability management or risk assessment, not a distinct phase within the incident response process itself.
Vulnerability management is a proactive process for identifying, assessing, and remediating vulnerabilities, which is separate from the reactive incident response process.
Risk assessment is a broader security governance activity that identifies, evaluates, and prioritizes risks, rather than a specific step in handling an ongoing security incident.
Concept tested: NIST incident response phases
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.