Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security

In the standard incident response lifecycle followed in cyber security practice, which phase comes immediately after 'Detection and Analysis'?

Containment, Eradication and Recovery follows Detection and Analysis. Once an incident is confirmed and understood, the team must limit its spread, remove the cause and restore systems. Lessons-learned review happens afterwards, and preparation is the initial phase of the lifecycle.

  1. APreparation
  2. BContainment, Eradication and RecoveryCorrect
  3. CPost-incident review
  4. DRisk acceptance

Explanation

The widely used lifecycle runs Preparation, Detection and Analysis, Containment/Eradication/Recovery, and then Post-incident activity. Preparation is the first phase, not the one after detection. The post-incident review occurs only after the incident has been contained and systems restored.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.

More Cyber Security questions