ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingMedium

A security team is performing a post-incident review following a data breach. They are examining logs, network captures, and endpoint detection and response (EDR) data to understand the attack's timeline, methods, and impact. Which phase of the incident response process are they currently engaged in?

  1. APost-Incident Recovery
  2. BContainment
  3. CEradication
  4. DIdentification
Show answer & explanation

Correct answer: A. Post-Incident Recovery

Examining logs and data to understand the attack's timeline and methods *after* a breach has occurred and been handled typically falls under the Post-Incident Recovery phase, which includes lessons learned, forensic analysis, and improving future response capabilities. While forensic analysis can happen during containment/eradication, a 'post-incident review' usually implies the formal analysis after immediate threat mitigation.

Why the other options are wrong

  • B. Containment focuses on limiting the scope and impact of the incident.
  • C. Eradication involves removing the root cause of the incident.
  • D. Identification is the initial detection of an incident.

Post-Incident Recovery

The final phase of incident response, focusing on restoring systems, conducting forensic analysis, documenting lessons learned, and improving future incident handling.

  • Occurs after the immediate threat is contained and eradicated.
  • Includes detailed forensic analysis and root cause identification.
  • Crucial for continuous improvement of security posture.

Memory trick: INCIDENT RESPONSE is a PREP plan, ID, CONTAIN, ERADICATE, RECOVER, and LESSONS cycle.

More Security Assessment and Testing questions