ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A security analyst is reviewing logs and notices a sudden, unexplained spike in network traffic originating from an internal server to an unknown external IP address. This server typically has minimal outbound traffic. Which phase of the incident response process would this observation typically fall under?
- AEradication
- BRecovery
- CDetection and Analysis
- DContainment
Show answer & explanationAnswer & explanation
Correct answer: C. Detection and Analysis
Observing an unexplained spike in network traffic and attempting to understand its nature falls squarely within the Detection and Analysis phase of incident response.
Why the other options are wrong
- A. Eradication involves removing the cause of the incident.
- B. Recovery focuses on restoring affected systems and services to normal operation.
- D. Containment aims to limit the scope and impact of an incident.
Incident Response (Detection and Analysis)
The phase of incident response where security events are identified, characterized, and assessed to determine if they constitute an incident.
- Involves monitoring systems, logs, and alerts.
- Aims to confirm an incident and gather initial information.
- Leads to subsequent phases like containment and eradication.
Memory trick: PREPARE for an incident, DETECT and ANALYZE it, CONTAIN its spread, ERADICATE the cause, RECOVER systems, and then POST-INCIDENT lessons learn.