nerdexam
Cisco

200-201 · Question #484

A network engineer informed a security team of a large amount of traffic and suspicious activity from an unknown source to the company DMZ server. The security team reviewed the data and identified a

The correct answer is B. detection and analysis. In this scenario, the security team is in the process of reviewing data and identifying a potential DDoS attempt. This phase is known as Detection and Analysis in the NIST incident response framework, where the team is responsible for detecting potential incidents and analyzing t

Submitted by kavita_s· Mar 6, 2026Security Policies and Procedures

Question

A network engineer informed a security team of a large amount of traffic and suspicious activity from an unknown source to the company DMZ server. The security team reviewed the data and identified a potential DDoS attempt. According to NIST, at which phase of incident response is the security team?

Options

  • Acontainment and eradication
  • Bdetection and analysis
  • Crecovery
  • Dpreparation

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    94% (29)
  • C
    3% (1)

Explanation

In this scenario, the security team is in the process of reviewing data and identifying a potential DDoS attempt. This phase is known as Detection and Analysis in the NIST incident response framework, where the team is responsible for detecting potential incidents and analyzing them to determine the scope, impact, and nature of the threat. The Containment and Eradication phase comes after detection and analysis, where actions are taken to limit the damage and eliminate the Since the team is still identifying the issue, they have not reached this phase yet. The Recovery phase focuses on restoring affected systems and returning them to normal operation after the incident has been contained and eradicated. The team is not in this phase as they are still analyzing the potential attack. The Preparation phase involves setting up tools, policies, and procedures to be ready for potential incidents. Since the team is already responding to suspicious activity, they are beyond the preparation stage.

Topics

#NIST SP 800-61#incident response#detection and analysis#DDoS

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice