Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingEasy
A security analyst receives an alert indicating unusual outbound network traffic from an internal server to an unknown external IP address on a non-standard port. The analyst confirms that this traffic is not part of any legitimate business process. Which phase of the incident response process should the analyst immediately focus on?
- APreparation
- BDetection and Analysis
- CContainment, Eradication, and Recovery
- DPost-Incident Activity
Show answer & explanationAnswer & explanation
Correct answer: B. Detection and Analysis
The analyst has received an alert and is now actively investigating to confirm the nature of the event. This falls under the Detection and Analysis phase, where an organization identifies, assesses, and understands the scope of an incident.
Why the other options are wrong
- A. Preparation occurs before any incident takes place.
- C. Containment, Eradication, and Recovery phases happen after the incident has been detected and analyzed.
- D. Post-Incident Activity occurs after the incident has been resolved.
Detection & Analysis
The phase of incident response where security events are identified, evaluated, and confirmed as security incidents, determining their nature and scope.
- Involves monitoring systems for anomalies.
- Includes initial triage and investigation.
- Aims to understand the incident's impact and characteristics.
Memory trick: Prepare to Detect, Contain, Eradicate, Recover, and Post-Analyze.