CERTIFIED-IN-CYBERSECURITY · Question #49
In which of the following phases of an Incident Recovery Plan are incident responses prioritized?
The correct answer is B. Detection and Analysis. According to NIST SP 800-61 (Computer Security Incident Handling Guide), the Detection and Analysis phase is where security teams identify, validate, and characterize incidents. Critically, this is also the phase where incidents are prioritized based on their potential business…
Question
In which of the following phases of an Incident Recovery Plan are incident responses prioritized?
Options
- APreparation
- BDetection and Analysis
- CPost-incident Activity
- DContentment, Eradication, and Recovery
How the community answered
(42 responses)- A5% (2)
- B93% (39)
- D2% (1)
Explanation
According to NIST SP 800-61 (Computer Security Incident Handling Guide), the Detection and Analysis phase is where security teams identify, validate, and characterize incidents. Critically, this is also the phase where incidents are prioritized based on their potential business impact, scope, data sensitivity, and criticality - determining how urgently resources should be mobilized. Preparation focuses on readiness, Post-Incident Activity covers lessons learned, and Containment/Eradication/Recovery focuses on resolving the incident after it has already been prioritized.
Topics
Community Discussion
No community discussion yet for this question.