SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium
A security team is conducting a vulnerability scan on a web application. The scan identifies several potential SQL injection vulnerabilities. Which of the following phases of the incident response life cycle would these findings primarily inform?
- AEradication
- BRecovery
- CPreparation
- DDetection and Analysis
Show answer & explanationAnswer & explanation
Correct answer: C. Preparation
Vulnerability scanning, when conducted proactively, is part of the 'Preparation' phase of incident response. It helps identify weaknesses before an incident occurs, allowing for proactive remediation to prevent future incidents.
Why the other options are wrong
- A. Eradication involves removing the cause of an actual incident after it has occurred.
- B. Recovery involves restoring systems after an incident has been eradicated.
- D. Detection and Analysis occurs when an actual incident is suspected or confirmed, not during proactive scanning.
Incident Preparation
The Incident Preparation phase involves establishing policies, procedures, and resources to prevent and effectively respond to cybersecurity incidents.
- Includes security awareness training.
- Develops incident response plans.
- Involves vulnerability assessments and patching.
Memory trick: Prepare for the storm before it hits, so you can detect, contain, eradicate, and recover.