SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium

A security auditor is reviewing an organization's incident response plan. The auditor notes that the plan includes steps for containment, eradication, and recovery, but lacks clear guidance on how to initially identify and confirm a security breach. Which phase of the incident response process is inadequately addressed?

  1. APreparation
  2. BContainment, Eradication, and Recovery
  3. CDetection and Analysis
  4. DPost-Incident Activity
Show answer & explanation

Correct answer: C. Detection and Analysis

The 'Detection and Analysis' phase of incident response is responsible for identifying, validating, and prioritizing security incidents. The scenario explicitly states a lack of guidance on how to 'initially identify and confirm a security breach', directly pointing to this phase.

Why the other options are wrong

  • A. Preparation involves proactive measures before an incident, not the reaction to a breach.
  • B. Containment, Eradication, and Recovery are explicitly mentioned as being present, so this phase is not inadequately addressed.
  • D. Post-Incident Activity occurs after recovery, involving lessons learned and reporting.

Incident Response - Detection and Analysis

The phase of incident response focused on identifying potential security events, determining if they are actual incidents, assessing their scope and impact, and prioritizing them for further action.

  • Involves monitoring logs and alerts.
  • Requires verifying the legitimacy of an incident.
  • Includes initial damage assessment and prioritization.

Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Post-mortem.

More Security Operations and Administration questions