nerdexam
CompTIA

CAS-003 · Question #587

A company recently experienced a security incident in which its domain controllers were the target of a DoS attack. In which of the following steps should technicians connect domain controllers to…

The correct answer is E. Recovery. Reconnecting domain controllers and resuming authentication services for users is a Recovery phase activity in the incident response lifecycle.

Enterprise Security Operations

Question

A company recently experienced a security incident in which its domain controllers were the target of a DoS attack. In which of the following steps should technicians connect domain controllers to the network and begin authenticating users again?

Options

  • APreparation
  • BIdentification
  • CContainment
  • DEradication
  • ERecovery
  • FLessons learned

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    3% (1)
  • E
    89% (31)
  • F
    3% (1)

Why each option

Reconnecting domain controllers and resuming authentication services for users is a Recovery phase activity in the incident response lifecycle.

APreparation

Preparation involves building incident response capabilities and procedures before any incident occurs, not restoring systems after an attack.

BIdentification

Identification is the phase where the security team detects and confirms an incident has occurred, not the phase where services are restored.

CContainment

Containment limits the spread or further damage of an active attack and does not involve reconnecting affected infrastructure to production.

DEradication

Eradication removes the root cause or threat artifacts from the environment, which must be completed before safe recovery can begin.

ERecoveryCorrect

Recovery is the incident response phase focused on restoring affected systems and services to normal, verified operation after the threat has been eliminated. Reconnecting domain controllers to the network and allowing users to authenticate again is the definition of service restoration, which is the primary objective of Recovery. This phase follows Eradication and precedes the Lessons Learned review.

FLessons learned

Lessons learned is a post-incident review conducted after full recovery to improve future response plans and is not an operational restoration step.

Concept tested: Incident response lifecycle - Recovery phase

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response phases#recovery#DoS attack#domain controller

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice