Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A security auditor is reviewing the incident response plan for a critical infrastructure organization. The plan outlines specific steps for isolating compromised systems, eradicating malware, and restoring affected services from backups. Which phase of the incident response lifecycle do these actions primarily fall under?

  1. AContainment, Eradication, and Recovery
  2. BPost-Incident Activity
  3. CDetection and Analysis
  4. DPreparation
Show answer & explanation

Correct answer: A. Containment, Eradication, and Recovery

The incident response lifecycle typically includes phases like Preparation, Detection and Analysis, Containment, Eradication, Recovery, and Post-Incident Activity. Isolating systems (containment), eradicating malware (eradication), and restoring services (recovery) are all core activities within the 'Containment, Eradication, and Recovery' phase.

Why the other options are wrong

  • B. Post-Incident Activity involves lessons learned and improving future responses.
  • C. Detection and Analysis focuses on identifying and understanding the incident.
  • D. Preparation involves proactive measures before an incident, like training and planning.

Incident Response Lifecycle (NIST)

A structured approach to managing the aftermath of a security breach or cyberattack, typically involving phases like preparation, detection, containment, eradication, recovery, and post-incident analysis.

  • Developed by NIST (National Institute of Standards and Technology).
  • Provides a systematic framework for handling security incidents.
  • Aims to minimize damage and recovery time.
  • Includes proactive and reactive stages.

Memory trick: IR is a cycle: Prepare, Detect, Contain, Eradicate, Recover, then learn.

More Security Concepts questions