nerdexam
GIAC

GCIH · Question #748

During which phase of incident response would an analyst review the following data?

The correct answer is A. Preparation. The Preparation phase of incident response is when analysts review policies, playbooks, and baseline data to ensure readiness before an incident occurs.

Incident Response & Cyber Kill Chain

Question

During which phase of incident response would an analyst review the following data?

Exhibit

GCIH question #748 exhibit

Options

  • APreparation
  • BReconnaissance
  • CDetection
  • DEnumeration

How the community answered

(41 responses)
  • A
    90% (37)
  • B
    5% (2)
  • C
    2% (1)
  • D
    2% (1)

Why each option

The Preparation phase of incident response is when analysts review policies, playbooks, and baseline data to ensure readiness before an incident occurs.

APreparationCorrect

Preparation is the first phase of incident response per frameworks like NIST SP 800-61, during which analysts review and establish procedures, tools, and baselines. Activities such as reviewing documentation, threat intelligence, and system inventories occur here to ensure the team is ready to respond effectively.

BReconnaissance

Reconnaissance is a phase of an attacker's kill chain or attack lifecycle, not a recognized phase of the incident response process.

CDetection

Detection (or Detection and Analysis) is the IR phase where analysts identify that an incident has occurred, not where preparatory data is reviewed.

DEnumeration

Enumeration is a phase in an attack methodology used by threat actors, not a recognized phase of the incident response lifecycle.

Concept tested: Incident response lifecycle - Preparation phase activities

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response phases#preparation phase#IR lifecycle#PICERL

Community Discussion

No community discussion yet for this question.

Full GCIH Practice