nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #49

In which of the following phases of an Incident Recovery Plan are incident responses prioritized?

The correct answer is B. Detection and Analysis. According to NIST SP 800-61 (Computer Security Incident Handling Guide), the Detection and Analysis phase is where security teams identify, validate, and characterize incidents. Critically, this is also the phase where incidents are prioritized based on their potential business…

2. Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) Concepts

Question

In which of the following phases of an Incident Recovery Plan are incident responses prioritized?

Options

  • APreparation
  • BDetection and Analysis
  • CPost-incident Activity
  • DContentment, Eradication, and Recovery

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    93% (39)
  • D
    2% (1)

Explanation

According to NIST SP 800-61 (Computer Security Incident Handling Guide), the Detection and Analysis phase is where security teams identify, validate, and characterize incidents. Critically, this is also the phase where incidents are prioritized based on their potential business impact, scope, data sensitivity, and criticality - determining how urgently resources should be mobilized. Preparation focuses on readiness, Post-Incident Activity covers lessons learned, and Containment/Eradication/Recovery focuses on resolving the incident after it has already been prioritized.

Topics

#Incident Response Phases#Incident Prioritization#Detection and Analysis#Cyber Incident Management

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice