Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingEasy
A cybersecurity incident response team is developing a new incident response plan. They are currently focusing on establishing clear communication channels, defining roles and responsibilities for team members, and ensuring all necessary tools and resources are in place before any incident occurs. Which incident handling concept are they primarily addressing?
- AThreat Hunting
- BPreparation Phase
- CRansomware Playbook
- DIncident Prioritization
Show answer & explanationAnswer & explanation
Correct answer: B. Preparation Phase
Establishing communication channels, defining roles, and ensuring resources are all activities that take place proactively before an incident, which are key components of the Preparation phase in incident response.
Why the other options are wrong
- A. Threat Hunting is a proactive security activity, but distinct from incident response preparation.
- C. A ransomware playbook is a specific guide, not the overarching concept.
- D. Incident Prioritization occurs during the Detection and Analysis phase.
Preparation Phase
The initial phase of incident response focused on establishing policies, training personnel, and procuring tools to effectively handle future security incidents.
- Involves creating incident response policies and procedures.
- Includes training staff on their roles and responsibilities.
- Ensures necessary security tools and resources are available.
Memory trick: Prepare with Policies, People, and Tools.