GCIH · Question #197
You work as an Incident handler in Mariotrixt.Inc. You have followed the Incident handling process to handle the events and incidents. You identify Denial of Service attack (DOS) from a network…
The correct answer is A. Containment. After identifying a DoS attack, the next phase in the incident handling process is Containment, which limits damage and prevents the attack from spreading further.
Question
You work as an Incident handler in Mariotrixt.Inc. You have followed the Incident handling process to handle the events and incidents. You identify Denial of Service attack (DOS) from a network linked to your internal enterprise network. Which of the following phases of the Incident handling process should you follow next to handle this incident?
Options
- AContainment
- BPreparation
- CRecovery
- DIdentification
How the community answered
(28 responses)- A86% (24)
- B4% (1)
- C7% (2)
- D4% (1)
Why each option
After identifying a DoS attack, the next phase in the incident handling process is Containment, which limits damage and prevents the attack from spreading further.
Containment is the phase that immediately follows Identification in the standard incident handling lifecycle (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned). During Containment, responders take action to limit the scope and impact of the active DoS attack, such as isolating affected network segments or blocking malicious traffic sources. Skipping Containment would allow the attack to continue causing damage before eradication efforts can begin.
Preparation is the first phase of incident handling, completed before any incident occurs, and is not a reactive step taken after a threat has already been identified.
Recovery comes after Eradication and involves restoring systems to normal operation, which cannot happen before the attack has first been contained and eliminated.
Identification was the phase just completed - the DoS attack has already been identified, so revisiting this phase is not the correct next step.
Concept tested: Incident handling process phase sequence after identification
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.