🌍 All Study GuidesπŸ“Š DashboardπŸ“° BlogπŸ’‘ About
Google Cybersecurity Professional Certificate β€’ STUDY MODE

THE INCIDENT RESPONSE LIFECYCLE

QUESTION 1 OF 4

The first phase of the NIST Incident Response Lifecycle is Preparation. What are the other phases? Select three answers.

A
Detection and AnalysisCorrect Answer
B
Identify
C
Containment, Eradication, and RecoveryCorrect Answer
D
Post-Incident ActivityCorrect Answer
Explanation:

The three other phases of the NIST Incident Response Lifecycle are: Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity.

QUESTION 2 OF 4

What type of process is the NIST Incident Response Lifecycle?

A
CyclicalCorrect Answer
B
Synchronous
C
Linear
D
Observable
Explanation:

The NIST Incident Response Lifecycle is a cyclical process. This means that phases in the lifecycle can be revisited or repeated as incident investigations progress.

QUESTION 3 OF 4

Fill in the blank: An _____ is an observable occurrence on a network, system, or device.

A
investigation
B
incident
C
eventCorrect Answer
D
analysis
Explanation:

An event is an observable occurrence on a network, system, or device. All incidents are considered events, but not all events are considered incidents.

QUESTION 4 OF 4

A security professional investigates an incident. Their goal is to gain information about the 5 W's, which include what happened and why. What are the other W's? Select three answers.

A
When the incident took placeCorrect Answer
B
Which type of incident it was
C
Who triggered the incidentCorrect Answer
D
Where the incident took placeCorrect Answer
Explanation:

The other W's are: who triggered the incident, when the incident took place, and where the incident took place.

Ready to test your recall?

The first phase of the NIST Incident Response Lifecycle is Preparation. What are the other phases? Select three answers.

πŸ’‘Select all 3 correct answers before submitting (0 of 3 selected).
A
Detection and Analysis
B
Identify
C
Containment, Eradication, and Recovery
D
Post-Incident Activity

How confident are you in this answer?