SY0-301 · Question #532
The Chief Technical Officer (CTO) has tasked The Computer Emergency Response Team (CERT) to develop and update all Internal Operating Procedures and Standard Operating Procedures documentation in…
The correct answer is D. Preparation. The Incident Handling process (as defined by NIST and similar frameworks) includes Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. Preparation is the phase that occurs before any incident takes place and focuses on building the capability…
Question
The Chief Technical Officer (CTO) has tasked The Computer Emergency Response Team (CERT) to develop and update all Internal Operating Procedures and Standard Operating Procedures documentation in order to successfully respond to future incidents. Which of the following stages of the Incident Handling process is the team working on?
Options
- ALessons Learned
- BEradication
- CRecovery
- DPreparation
How the community answered
(27 responses)- A4% (1)
- B4% (1)
- D93% (25)
Explanation
The Incident Handling process (as defined by NIST and similar frameworks) includes Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. Preparation is the phase that occurs before any incident takes place and focuses on building the capability to respond - this includes creating and maintaining policies, procedures (IOPs, SOPs), training staff, acquiring tools, and establishing communication plans. Since the team is developing documentation to be ready for future incidents, this is clearly the Preparation phase. The other options (Lessons Learned, Eradication, Recovery) all occur after an incident has already begun.
Topics
Community Discussion
No community discussion yet for this question.