Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security

A company has implemented the NIST CSF. Its network team deploys an intrusion detection system that raises alerts on anomalous traffic, and later prepares a documented playbook to contain a confirmed intrusion. Which mapping of these two activities to NIST CSF functions is correct?

The intrusion detection system belongs to the Detect function because it discovers anomalous events, and the containment playbook belongs to Respond because it handles actions against a confirmed incident. Recover is about restoring normal operations afterwards, so placing containment there would be incorrect.

  1. AIntrusion detection under Detect; containment playbook under RespondCorrect
  2. BIntrusion detection under Protect; containment playbook under Recover
  3. CIntrusion detection under Identify; containment playbook under Protect
  4. DIntrusion detection under Respond; containment playbook under Detect

Explanation

Detect covers continuous monitoring and anomaly discovery, which an IDS performs. Containment of a confirmed incident falls under Respond. Placing the playbook in Recover is wrong because Recover addresses restoring services and capabilities after the incident.

Did you get it right without looking?

One question tells you little. A timed set on Network Basics and Security shows your real accuracy, how long you take and where you lose marks.

More Network Basics and Security questions