NSE7_SOC_AR-7.6 · Question #4
According to the National Institute of Standards and Technology (NIST) cybersecurity framework, incident handling activities can be divided into phases. In which incident handling phase do you…
The correct answer is A. Containment. During the Containment phase of incident handling according to the NIST cybersecurity framework, the goal is to limit the scope and magnitude of an incident. This includes isolating or quarantining compromised systems to prevent the adversary from further exploiting them or…
Question
According to the National Institute of Standards and Technology (NIST) cybersecurity framework, incident handling activities can be divided into phases. In which incident handling phase do you quarantine a compromised host in order to prevent an adversary from using it as a stepping stone to the next phase of an attack?
Options
- AContainment
- BAnalysis
- CEradication
- DRecovery
How the community answered
(51 responses)- A92% (47)
- B2% (1)
- C2% (1)
- D4% (2)
Explanation
During the Containment phase of incident handling according to the NIST cybersecurity framework, the goal is to limit the scope and magnitude of an incident. This includes isolating or quarantining compromised systems to prevent the adversary from further exploiting them or using them as a launch pad for attacks on additional systems. This phase is crucial for stopping the spread of the incident and preventing further damage.
Topics
Community Discussion
No community discussion yet for this question.