nerdexam
Cisco

200-201 · Question #288

An engineer is working on a ticket for an incident from the incident management team. A week ago, an external web application was targeted by a DDoS attack. Server resources were exhausted and after…

The correct answer is D. containment, eradication, and recovery. The engineer's actions align with the containment, eradication, and recovery phase of incident Containment: The engineer recommended implementing mitigation measures like Blackhole filtering to contain the impact of the DDoS attack on the external web application, preventing…

Submitted by stefanr· Mar 6, 2026Security Policies and Procedures

Question

An engineer is working on a ticket for an incident from the incident management team. A week ago, an external web application was targeted by a DDoS attack. Server resources were exhausted and after two hours, it crashed. An engineer was able to identify the attacker and technique used. Three hours after the attack, the server was restored and the engineer recommended implementing mitigation by Blackhole filtering and transferred the incident ticket back to the IR team. According to NIST.SP800-61, at which phase of the incident response did the engineer finish work?

Options

  • Apost-incident activity
  • Bpreparation
  • Cdetection and analysis
  • Dcontainment, eradication, and recovery

How the community answered

(41 responses)
  • A
    10% (4)
  • B
    5% (2)
  • C
    2% (1)
  • D
    83% (34)

Explanation

The engineer's actions align with the containment, eradication, and recovery phase of incident Containment: The engineer recommended implementing mitigation measures like Blackhole filtering to contain the impact of the DDoS attack on the external web application, preventing further damage or disruption. Eradication: The identification of the attacker and the technique used suggests efforts to eradicate the cause of the incident and prevent future occurrences of a similar nature. Recovery: The engineer's action of restoring the server three hours after the attack indicates recovery efforts to bring the affected system back to normal operation.

Topics

#NIST SP 800-61#Incident response#Containment#Recovery

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice