CRISC · Question #154
Which of the following is MOST important for successful incident response?
The correct answer is D. The timeliness of attack recognition. The timeliness of attack recognition is paramount for successful incident response, as prompt detection allows for quicker containment and minimized damage.
Question
Which of the following is MOST important for successful incident response?
Options
- AThe quantity of data logged by the attack control tools
- BBlocking the attack route immediately
- CThe ability to trace the source of the attack
- DThe timeliness of attack recognition
How the community answered
(33 responses)- B3% (1)
- C3% (1)
- D94% (31)
Why each option
The timeliness of attack recognition is paramount for successful incident response, as prompt detection allows for quicker containment and minimized damage.
While data logging is essential for investigation, the *quantity* alone doesn't guarantee success; timely analysis and action on relevant data are more critical than sheer volume.
Blocking the attack route is a critical *containment* step in incident response, but it can only occur *after* the attack has been recognized, making recognition a prerequisite.
Tracing the attack source is important for forensic analysis and preventing future incidents, but it is typically performed after initial containment and eradication, and is not the most immediate factor for successful response to an ongoing attack.
Early and accurate recognition of a security incident significantly reduces the window of opportunity for attackers, limits the scope of damage, and allows the incident response team to initiate containment, eradication, and recovery procedures more quickly. Delayed recognition can lead to prolonged compromise, data exfiltration, and higher recovery costs.
Concept tested: Incident response key factors
Source: https://www.nist.gov/privacy-framework/nist-sp-800-61-rev2-computer-security-incident-handling-guide
Topics
Community Discussion
No community discussion yet for this question.