ISC2 Certified in Cybersecurity (CC)Security PrinciplesHard
A security team is conducting a post-incident review after a successful phishing attack led to a small data breach. They are analyzing the steps taken from the moment the attack was detected until the breach was contained and eradicated. Which phase of the incident response process are they primarily focused on?
- APreparation
- BContainment, Eradication, & Recovery
- CDetection & Analysis
- DPost-Incident Activity
Show answer & explanationAnswer & explanation
Correct answer: D. Post-Incident Activity
The scenario describes a 'post-incident review' and 'analyzing the steps taken from detection to containment'. This retrospective analysis to learn from the incident and improve future responses is the core activity of the 'Post-Incident Activity' (or Lessons Learned) phase.
Why the other options are wrong
- A. Preparation involves establishing policies and tools before an incident occurs.
- B. Containment, Eradication, & Recovery are the actions taken during an active incident to stop, remove, and restore.
- C. Detection & Analysis involves identifying and understanding the incident as it happens.
Post-Incident Activity (Incident Response)
The final phase of the incident response process, focused on learning from the incident. It includes documentation, evidence retention, conducting a 'lessons learned' review, and improving policies and procedures.
- Aka 'Lessons Learned' phase
- Aims to prevent recurrence and improve future response
- Involves detailed analysis and reporting
Memory trick: PDRCER: Prepare, Detect, Contain, Eradicate, Recover, Post-incident.