CAS-003 · Question #587
A company recently experienced a security incident in which its domain controllers were the target of a DoS attack. In which of the following steps should technicians connect domain controllers to…
The correct answer is E. Recovery. Reconnecting domain controllers and resuming authentication services for users is a Recovery phase activity in the incident response lifecycle.
Question
A company recently experienced a security incident in which its domain controllers were the target of a DoS attack. In which of the following steps should technicians connect domain controllers to the network and begin authenticating users again?
Options
- APreparation
- BIdentification
- CContainment
- DEradication
- ERecovery
- FLessons learned
How the community answered
(35 responses)- A6% (2)
- B3% (1)
- E89% (31)
- F3% (1)
Why each option
Reconnecting domain controllers and resuming authentication services for users is a Recovery phase activity in the incident response lifecycle.
Preparation involves building incident response capabilities and procedures before any incident occurs, not restoring systems after an attack.
Identification is the phase where the security team detects and confirms an incident has occurred, not the phase where services are restored.
Containment limits the spread or further damage of an active attack and does not involve reconnecting affected infrastructure to production.
Eradication removes the root cause or threat artifacts from the environment, which must be completed before safe recovery can begin.
Recovery is the incident response phase focused on restoring affected systems and services to normal, verified operation after the threat has been eliminated. Reconnecting domain controllers to the network and allowing users to authenticate again is the definition of service restoration, which is the primary objective of Recovery. This phase follows Eradication and precedes the Lessons Learned review.
Lessons learned is a post-incident review conducted after full recovery to improve future response plans and is not an operational restoration step.
Concept tested: Incident response lifecycle - Recovery phase
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.