SSCP · Question #1151
Each of the following is a valid step in handling incidents except ____________
The correct answer is B. Prosecute. "Prosecute" is not a standard step in the cybersecurity incident response lifecycle, which focuses on technical and organizational actions to mitigate and learn from incidents.
Question
Each of the following is a valid step in handling incidents except ____________
Options
- AContain
- BProsecute
- CRecover
- DReview
- EIdentify
- FPrepare
How the community answered
(65 responses)- A2% (1)
- B88% (57)
- C2% (1)
- E6% (4)
- F3% (2)
Why each option
"Prosecute" is not a standard step in the cybersecurity incident response lifecycle, which focuses on technical and organizational actions to mitigate and learn from incidents.
Containment is a crucial step to limit the scope and impact of an incident.
The standard incident response process, often guided by frameworks like NIST SP 800-61, includes phases such as Preparation, Identification, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned/Review). While legal action might follow an incident, "prosecute" is a legal action taken by law enforcement or legal teams, not a direct step in the technical and operational incident handling process.
Recovery is a vital step to restore affected systems and services to normal operation.
Review (or Lessons Learned) is essential for improving future incident response capabilities.
Identification is the initial step of determining whether an event is indeed an incident.
Preparation is the foundational step that ensures an organization is ready to handle incidents effectively.
Concept tested: Incident response lifecycle (NIST SP 800-61)
Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.