nerdexam
Cisco

350-201(NEW-127Q) · Question #99

An IT security team detects an unauthorized access to their development environment on few QA team machines. According to the incident response workflow, which sequence of actions should the team…

The correct answer is D. Contain the breach, identify the affected systems, eradicate the threat, recover systems, and conduct a post-incident review. Option D correctly follows the industry-standard incident response lifecycle (per NIST SP 800-61): you must first contain the breach to prevent further spread, then identify the full scope of affected systems, eradicate the threat once you understand it, recover systems to…

Incident Response and Management

Question

An IT security team detects an unauthorized access to their development environment on few QA team machines. According to the incident response workflow, which sequence of actions should the team follow to address the incident?

Options

  • AImmediately recover affected systems, identify the breach, contain the threat, and then review incident response effectiveness.
  • BPrioritize threat eradication, followed by system recovery, breach containment, and ending with identifying affected systems.
  • CIsolate the affected machines, eradicate the identified threat, recover the affected systems, and conduct post-mortem.
  • DContain the breach, identify the affected systems, eradicate the threat, recover systems, and conduct a post-incident review.

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    14% (5)
  • D
    74% (26)

Explanation

Option D correctly follows the industry-standard incident response lifecycle (per NIST SP 800-61): you must first contain the breach to prevent further spread, then identify the full scope of affected systems, eradicate the threat once you understand it, recover systems to normal operation, and finally conduct a post-incident review to improve future defenses.

A is wrong because it begins with recovery before the threat is even identified or contained - you can't safely restore systems while the attacker still has access.

B is wrong because it attempts eradication first, which is impossible without first knowing what systems are affected and containing the spread; it also illogically places containment after eradication.

C is the trickiest distractor - isolation (containment) is correct as the first step, but it skips the critical identification/analysis phase before eradication, meaning you could eradicate the wrong thing or miss compromised systems entirely.

Memory tip: Use the acronym C-I-E-R-P - "Can I Eradicate Really Properly?" - Contain, Identify, Eradicate, Recover, Post-incident review. The key insight is that you must know before you act: contain first to stop the bleeding, then analyze before you eradicate.

Topics

#Incident Response#IR Procedures#Threat Containment#Security Operations

Community Discussion

No community discussion yet for this question.

Full 350-201(NEW-127Q) Practice