nerdexam
Cisco

300-220 · Question #10

A runbook or playbook for a detectable scenario should include:

The correct answer is B. Steps for containment, eradication, and recovery. Option B is correct because a runbook (or playbook) is an operational document designed to guide incident responders through a structured process when a known threat scenario is detected - the core phases of that process are containment (stopping the spread), eradication…

Threat Hunting Processes

Question

A runbook or playbook for a detectable scenario should include:

Options

  • AThe CEO's contact information
  • BSteps for containment, eradication, and recovery
  • CA list of favorite employee lunch spots
  • DCorporate holiday schedules

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    89% (25)
  • C
    7% (2)

Explanation

Option B is correct because a runbook (or playbook) is an operational document designed to guide incident responders through a structured process when a known threat scenario is detected - the core phases of that process are containment (stopping the spread), eradication (removing the threat), and recovery (restoring normal operations). These three steps map directly to the NIST and SANS incident response frameworks that security certifications test on. Options A, C, and D are all organizationally irrelevant to incident response: CEO contact info belongs in an escalation or communications plan (not a technical runbook), lunch spots and holiday schedules have no bearing on handling a security incident whatsoever.

Memory tip: Think of a runbook as a firefighter's drill card - when the alarm sounds, you need what to do, not who to call for lunch. The three action verbs - Contain, Eradicate, Recover - spell CER, which you can remember as "Certainly Every Responder" needs these steps.

Topics

#Incident Response Playbook#Containment and Recovery#Threat Detection Response#Runbook Development

Community Discussion

No community discussion yet for this question.

Full 300-220 Practice