Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresEasy
A security analyst is reviewing network logs and discovers multiple failed login attempts from an external IP address targeting a critical internal server. The organization's incident response plan outlines specific steps for validating, categorizing, and escalating such events. Which phase of the incident response process is the analyst currently engaged in?
- ADetection and Analysis
- BPreparation
- CEradication
- DPost-Incident Activity
Show answer & explanationAnswer & explanation
Correct answer: A. Detection and Analysis
The analyst is reviewing logs and discovering an event, then validating and categorizing it, which are all activities within the Detection and Analysis phase of incident response.
Why the other options are wrong
- B. Preparation involves proactive measures before an incident occurs, like developing the IR plan.
- C. Eradication involves removing the cause of the incident, which comes after detection and analysis.
- D. Post-Incident Activity involves lessons learned and improving processes after an incident is resolved.
Incident Response Life Cycle
A structured approach to handling and managing the aftermath of a security breach or cyberattack. It aims to minimize damage and recovery time.
- Typically involves several phases.
- Ensures a systematic and efficient response.
- Helps organizations recover quickly and learn from incidents.
Memory trick: Prepare, find, fix, recover, learn, repeat.