CISA · Question #21
The operations team of an organization has reported an IS security attack. Which of the following should be the FIRST step for the security incident response team?
The correct answer is C. Perform a damage assessment.. When an IS security attack is reported, the incident response team's immediate priority is to assess the extent and impact of the damage caused by the incident.
Question
The operations team of an organization has reported an IS security attack. Which of the following should be the FIRST step for the security incident response team?
Options
- AReport results to management.
- BDocument lessons learned.
- CPerform a damage assessment.
- DPrioritize resources for corrective action.
How the community answered
(26 responses)- A4% (1)
- B4% (1)
- C85% (22)
- D8% (2)
Why each option
When an IS security attack is reported, the incident response team's immediate priority is to assess the extent and impact of the damage caused by the incident.
Reporting results to management comes after initial assessment and containment, once there are substantial findings and a clearer understanding of the situation to communicate.
Documenting lessons learned is part of the post-incident phase, intended for improving future incident response capabilities and is not an immediate first step.
Performing a damage assessment is the crucial first step in incident response because it allows the team to understand the scope of the attack, identify affected systems and data, and determine the severity of the breach. This information is essential for effective containment, eradication, and recovery efforts, guiding all subsequent actions.
Prioritizing resources for corrective action occurs after the damage is assessed and containment strategies are being planned based on the incident's impact and scope.
Concept tested: Incident response first steps
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.