nerdexam
GIAC

GCIH · Question #199

You work as a Senior Marketing Manager for Umbrella Inc. You find out that some of the software applications on the systems were malfunctioning and also you were not able to access your remote…

The correct answer is D. Identification. The incident response team performed the Identification phase by investigating the event, gathering information, and determining it was a controlled event rather than an actual incident.

Incident Response & Cyber Kill Chain

Question

You work as a Senior Marketing Manager for Umbrella Inc. You find out that some of the software applications on the systems were malfunctioning and also you were not able to access your remote desktop session. You suspected that some malicious attack was performed on the network of the company. You immediately called the incident response team to handle the situation who enquired the Network Administrator to acquire all relevant information regarding the malfunctioning. The Network Administrator informed the incident response team that he was reviewing the security of the network which caused all these problems. Incident response team announced that this was a controlled event not an incident. Which of the following steps of an incident handling process was performed by the incident response team?

Options

  • AContainment
  • BEradication
  • CPreparation
  • DIdentification

How the community answered

(51 responses)
  • A
    10% (5)
  • B
    4% (2)
  • C
    2% (1)
  • D
    84% (43)

Why each option

The incident response team performed the Identification phase by investigating the event, gathering information, and determining it was a controlled event rather than an actual incident.

AContainment

Containment involves taking action to limit the impact of a confirmed incident, but no incident was confirmed here - the event was declared controlled and benign.

BEradication

Eradication involves removing malicious artifacts or threats from affected systems, which is not applicable when no actual attack or compromise occurred.

CPreparation

Preparation is a pre-incident phase focused on building capabilities and policies before incidents occur, not an investigative step performed in reaction to an observed event.

DIdentificationCorrect

The Identification phase involves detecting events, analyzing them, and determining whether they constitute an actual security incident or a benign and controlled event. In this scenario, the team gathered information from the Network Administrator, reviewed the circumstances, and concluded the disruption was caused by a planned security review - not a malicious attack. This act of distinguishing an incident from a non-incident is the core function of the Identification phase.

Concept tested: Incident identification and event vs. incident classification

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident handling#identification phase#false positive triage#incident classification

Community Discussion

No community discussion yet for this question.

Full GCIH Practice