nerdexam
Cisco

350-201 · Question #76

The incident response team was notified of detected malware. The team identified the infected hosts, removed the malware, restored the functionality and data of infected systems, and planned a…

The correct answer is A. Contain the malware. The NIST SP 800-61 incident handling lifecycle requires Containment to occur before Eradication and Recovery, and the team skipped this critical step.

Processes

Question

The incident response team was notified of detected malware. The team identified the infected hosts, removed the malware, restored the functionality and data of infected systems, and planned a company meeting to improve the incident handling capability. Which step was missed according to the NIST incident handling guide?

Options

  • AContain the malware
  • BInstall IPS software
  • CDetermine the escalation path
  • DPerform vulnerability assessment

How the community answered

(47 responses)
  • A
    85% (40)
  • B
    9% (4)
  • C
    2% (1)
  • D
    4% (2)

Why each option

The NIST SP 800-61 incident handling lifecycle requires Containment to occur before Eradication and Recovery, and the team skipped this critical step.

AContain the malwareCorrect

According to NIST SP 800-61, the correct order of steps is Detection and Analysis, Containment, Eradication, and Recovery. The team jumped from identifying infected hosts directly to eradication (removing malware) and recovery (restoring systems) without first containing the threat. Containment isolates infected systems to prevent the malware from spreading laterally to other hosts on the network.

BInstall IPS software

Installing IPS software is a proactive or preparation-phase measure, not a required step within the NIST incident response lifecycle sequence.

CDetermine the escalation path

Escalation path determination is part of the Detection and Analysis phase, which the team effectively completed by identifying infected hosts.

DPerform vulnerability assessment

Vulnerability assessment is a post-incident or preparation activity and is not a required sequential step within the NIST incident handling phases.

Concept tested: NIST SP 800-61 incident response lifecycle order

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#NIST incident handling#containment#IR procedures#incident lifecycle

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice