nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #248

What phase of the incident response process is aimed at minimizing the impact or extent of an incident?

The correct answer is A. Containment. The standard incident response lifecycle (per NIST SP 800-61) includes: Preparation, Detection & Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Containment is the phase specifically focused on limiting the spread and impact of an incident - for example…

Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts

Question

What phase of the incident response process is aimed at minimizing the impact or extent of an incident?

Options

  • AContainment
  • BResponse
  • CDetection
  • DRecovery

How the community answered

(43 responses)
  • A
    86% (37)
  • B
    2% (1)
  • C
    2% (1)
  • D
    9% (4)

Explanation

The standard incident response lifecycle (per NIST SP 800-61) includes: Preparation, Detection & Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Containment is the phase specifically focused on limiting the spread and impact of an incident - for example, isolating an infected host from the network. Detection identifies that an incident occurred; Recovery restores normal operations; 'Response' is too broad a term to be a distinct phase in this context.

Topics

#Incident Response#Containment#Cybersecurity Operations#Security Incident Management

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice