Palo Alto Networks Certified Security Automation Engineer (PCSAE)Incident ManagementMedium
A security analyst is responding to a malware infection incident. They have completed the containment and eradication phases, and now need to ensure all affected systems are fully restored to a secure state, and post-incident checks are performed. This includes verifying system integrity, updating antivirus definitions, and ensuring backups are functional. According to the NIST Incident Response Lifecycle, which phase are they currently in?
- AIdentification
- BPost-Incident Activity
- CRecovery
- DContainment
Show answer & explanationAnswer & explanation
Correct answer: C. Recovery
The Recovery phase of the NIST Incident Response Lifecycle focuses on restoring affected systems and services to operational status, verifying their integrity, and ensuring they are secure after an incident.
Why the other options are wrong
- A. Identification is about detecting and confirming the incident.
- B. Post-Incident Activity (or Lessons Learned) comes after recovery and focuses on analysis and improvements.
- D. Containment is about limiting the scope and preventing further damage.
NIST Incident Response Lifecycle - Recovery
The Recovery phase of the NIST Incident Response Lifecycle focuses on restoring affected systems and services to operational status, verifying their integrity, and ensuring they are secure after the eradication of the threat.
- Includes restoring data from backups.
- Involves testing and validating system functionality.
- Aims to return operations to business as usual securely.
Memory trick: Prepared, identified, contained, eradicated, recovered, lessons learned.