CISA · Question #45
Which of the following should be the FIRST step in the incident response process for a suspected breach?
The correct answer is D. Research the validity of the alerted breach.. The immediate first step in incident response for a suspected breach is to research and validate the alert to confirm it is a genuine incident.
Question
Which of the following should be the FIRST step in the incident response process for a suspected breach?
Options
- AEngage a third party to independently evaluate the alerted breach.
- BNotify business management of the security breach.
- CInform potentially affected customers of the security breach.
- DResearch the validity of the alerted breach.
How the community answered
(39 responses)- A5% (2)
- B3% (1)
- D92% (36)
Why each option
The immediate first step in incident response for a suspected breach is to research and validate the alert to confirm it is a genuine incident.
Engaging a third party is typically done after initial identification and assessment, especially for complex or confirmed incidents, not as the very first step when an alert is first received.
Notifying business management is part of the communication plan, which follows the identification and initial assessment of a confirmed incident, not the validation of the initial alert.
Informing potentially affected customers is a late-stage step in the incident response process, typically after containment, eradication, recovery, and legal notification requirements have been determined.
The incident response process begins with the 'Identification' phase, where the primary objective is to determine if an actual security incident has occurred and assess its nature and scope. Researching the validity of the alerted breach prevents the allocation of resources to false positives and ensures subsequent, resource-intensive steps are taken only for confirmed incidents.
Concept tested: Incident response identification phase
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev2/final
Topics
Community Discussion
No community discussion yet for this question.