nerdexam
Cisco

200-201 · Question #272

Which two elements of the incident response process are stated in NIST SP 800-61 r2? (Choose two.)

The correct answer is A. detection and analysis B. post-incident activity. NIST SP 800-61 Rev. 2 outlines the Incident Response Lifecycle, which includes distinct phases for actively identifying and analyzing security incidents, as well as conducting crucial follow-up activities.

Submitted by miguelv· Mar 6, 2026Security Policies and Procedures

Question

Which two elements of the incident response process are stated in NIST SP 800-61 r2? (Choose two.)

Options

  • Adetection and analysis
  • Bpost-incident activity
  • Cvulnerability scoring
  • Dvulnerability management
  • Erisk assessment

How the community answered

(20 responses)
  • A
    90% (18)
  • C
    5% (1)
  • D
    5% (1)

Why each option

NIST SP 800-61 Rev. 2 outlines the Incident Response Lifecycle, which includes distinct phases for actively identifying and analyzing security incidents, as well as conducting crucial follow-up activities.

Adetection and analysisCorrect

'Detection and Analysis' is a core phase in the NIST incident response lifecycle, focusing on identifying security events, determining if they are incidents, and analyzing their scope and nature.

Bpost-incident activityCorrect

'Post-Incident Activity' is the final phase of the NIST incident response process, involving lessons learned, evidence retention, and using findings to improve future incident handling and overall security posture.

Cvulnerability scoring

Vulnerability scoring is typically part of vulnerability management or risk assessment, not a distinct phase within the incident response process itself.

Dvulnerability management

Vulnerability management is a proactive process for identifying, assessing, and remediating vulnerabilities, which is separate from the reactive incident response process.

Erisk assessment

Risk assessment is a broader security governance activity that identifies, evaluates, and prioritizes risks, rather than a specific step in handling an ongoing security incident.

Concept tested: NIST incident response phases

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#NIST SP 800-61#Incident response phases#Detection#Post-incident activity

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice