ISC2 Certified in Cybersecurity (CC)Business Continuity (BC), Disaster Recovery (DR) & Incident Response (IR) ConceptsHard
A security operations center (SOC) receives an alert indicating unusual outbound network traffic from an internal server to an unknown external IP address. After initial investigation, it's determined to be a data exfiltration attempt. The SOC team then follows documented procedures to contain the threat and gather evidence. This structured approach is best described as:
- AIncident Response Planning
- BRisk Management
- CVulnerability Management
- DSecurity Audit
Show answer & explanationAnswer & explanation
Correct answer: A. Incident Response Planning
Incident Response Planning (IRP) involves developing and documenting the structured procedures and processes an organization follows to prepare for, detect, contain, eradicate, recover from, and learn from security incidents. The scenario describes the SOC team following 'documented procedures' to handle a 'data exfiltration attempt,' which is a direct application of an IRP.
Why the other options are wrong
- B. Risk management is a broader process of identifying, assessing, and mitigating risks, of which incident response is a part, but not the specific 'structured approach' to an active incident.
- C. Vulnerability management focuses on identifying, assessing, and remediating security weaknesses, not responding to active incidents.
- D. A security audit is an independent examination of an organization's security posture, not an active response to an incident.
Incident Response Planning (IRP)
The process of creating and maintaining a structured, documented approach that an organization will follow to prepare for, detect, contain, eradicate, recover from, and learn from security incidents.
- Defines roles, responsibilities, and communication channels.
- Outlines specific procedures for various types of incidents.
- A critical component of an overall cybersecurity strategy.
Memory trick: IRP: 'I'ncident 'R'esponse 'P'lan, your playbook for cyber-attacks.