CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Network Basics and Security
A company has implemented the NIST CSF. Its network team deploys an intrusion detection system that raises alerts on anomalous traffic, and later prepares a documented playbook to contain a confirmed intrusion. Which mapping of these two activities to NIST CSF functions is correct?
The intrusion detection system belongs to the Detect function because it discovers anomalous events, and the containment playbook belongs to Respond because it handles actions against a confirmed incident. Recover is about restoring normal operations afterwards, so placing containment there would be incorrect.
- AIntrusion detection under Detect; containment playbook under RespondCorrect
- BIntrusion detection under Protect; containment playbook under Recover
- CIntrusion detection under Identify; containment playbook under Protect
- DIntrusion detection under Respond; containment playbook under Detect
Explanation
Detect covers continuous monitoring and anomaly discovery, which an IDS performs. Containment of a confirmed incident falls under Respond. Placing the playbook in Recover is wrong because Recover addresses restoring services and capabilities after the incident.
Did you get it right without looking?
One question tells you little. A timed set on Network Basics and Security shows your real accuracy, how long you take and where you lose marks.
More Network Basics and Security questions
- A Mumbai firm finds that an attacker, after gaining access without authority, copied customer data from its network and deleted logs. Which …
- In TCP/IP, which protocol pair is correctly matched with its layer?
- A company secretary is asked why a laptop connected to an office Wi-Fi network is able to receive a different IP address each time it reconn…
- A company secretary of a firm in Pune is asked to describe the network connecting the firm's head office floors and its server room within a…
- Which of the following correctly distinguishes the internet from an intranet in an organisation?
- Under the Information Technology Act, 2000, a person who knowingly conceals or alters computer source code used for a computer network, when…