The three other phases of the NIST Incident Response Lifecycle are: Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity.
The NIST Incident Response Lifecycle is a cyclical process. This means that phases in the lifecycle can be revisited or repeated as incident investigations progress.
An event is an observable occurrence on a network, system, or device. All incidents are considered events, but not all events are considered incidents.
The other W's are: who triggered the incident, when the incident took place, and where the incident took place.
The first phase of the NIST Incident Response Lifecycle is Preparation. What are the other phases? Select three answers.
How confident are you in this answer?