350-201 · Question #76
The incident response team was notified of detected malware. The team identified the infected hosts, removed the malware, restored the functionality and data of infected systems, and planned a…
The correct answer is A. Contain the malware. The NIST SP 800-61 incident handling lifecycle requires Containment to occur before Eradication and Recovery, and the team skipped this critical step.
Question
The incident response team was notified of detected malware. The team identified the infected hosts, removed the malware, restored the functionality and data of infected systems, and planned a company meeting to improve the incident handling capability. Which step was missed according to the NIST incident handling guide?
Options
- AContain the malware
- BInstall IPS software
- CDetermine the escalation path
- DPerform vulnerability assessment
How the community answered
(47 responses)- A85% (40)
- B9% (4)
- C2% (1)
- D4% (2)
Why each option
The NIST SP 800-61 incident handling lifecycle requires Containment to occur before Eradication and Recovery, and the team skipped this critical step.
According to NIST SP 800-61, the correct order of steps is Detection and Analysis, Containment, Eradication, and Recovery. The team jumped from identifying infected hosts directly to eradication (removing malware) and recovery (restoring systems) without first containing the threat. Containment isolates infected systems to prevent the malware from spreading laterally to other hosts on the network.
Installing IPS software is a proactive or preparation-phase measure, not a required step within the NIST incident response lifecycle sequence.
Escalation path determination is part of the Detection and Analysis phase, which the team effectively completed by identifying infected hosts.
Vulnerability assessment is a post-incident or preparation activity and is not a required sequential step within the NIST incident handling phases.
Concept tested: NIST SP 800-61 incident response lifecycle order
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.