nerdexam
Fortinet

NSE7_SOC_AR-7.6 · Question #4

According to the National Institute of Standards and Technology (NIST) cybersecurity framework, incident handling activities can be divided into phases. In which incident handling phase do you…

The correct answer is A. Containment. During the Containment phase of incident handling according to the NIST cybersecurity framework, the goal is to limit the scope and magnitude of an incident. This includes isolating or quarantining compromised systems to prevent the adversary from further exploiting them or…

SOC Best Practices and Incident Response

Question

According to the National Institute of Standards and Technology (NIST) cybersecurity framework, incident handling activities can be divided into phases. In which incident handling phase do you quarantine a compromised host in order to prevent an adversary from using it as a stepping stone to the next phase of an attack?

Options

  • AContainment
  • BAnalysis
  • CEradication
  • DRecovery

How the community answered

(51 responses)
  • A
    92% (47)
  • B
    2% (1)
  • C
    2% (1)
  • D
    4% (2)

Explanation

During the Containment phase of incident handling according to the NIST cybersecurity framework, the goal is to limit the scope and magnitude of an incident. This includes isolating or quarantining compromised systems to prevent the adversary from further exploiting them or using them as a launch pad for attacks on additional systems. This phase is crucial for stopping the spread of the incident and preventing further damage.

Topics

#NIST framework#incident handling phases#containment#host quarantine

Community Discussion

No community discussion yet for this question.

Full NSE7_SOC_AR-7.6 Practice