GCIH · Question #63
You are an Incident manager in Orangesect.Inc. You have been tasked to set up a new extension of your enterprise. The networking, to be done in the new extension, requires different types of cables…
The correct answer is D. Preparation. The Preparation stage of incident handling involves establishing policies, procedures, and infrastructure before incidents occur, including decisions about network setup and policy.
Question
You are an Incident manager in Orangesect.Inc. You have been tasked to set up a new extension of your enterprise. The networking, to be done in the new extension, requires different types of cables and an appropriate policy that will be decided by you. Which of the following stages in the Incident handling process involves your decision making?
Options
- AIdentification
- BContainment
- CEradication
- DPreparation
How the community answered
(41 responses)- A2% (1)
- B7% (3)
- C2% (1)
- D88% (36)
Why each option
The Preparation stage of incident handling involves establishing policies, procedures, and infrastructure before incidents occur, including decisions about network setup and policy.
Identification involves detecting and recognizing that an incident has occurred, not making pre-incident infrastructure or policy decisions.
Containment involves limiting the spread or impact of an active incident after it has already been identified.
Eradication involves removing the root cause of an incident, such as deleting malware or closing vulnerabilities, after containment.
Preparation is the first phase of the incident handling process where organizations define security policies, deploy networking infrastructure, assign roles, and make architectural decisions - exactly what the scenario describes when setting up a new enterprise extension with cabling decisions and policy creation.
Concept tested: Incident handling process - Preparation phase
Source: https://www.nist.gov/publications/computer-security-incident-handling-guide
Topics
Community Discussion
No community discussion yet for this question.