CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
In the standard incident response lifecycle followed in cyber security practice, which phase comes immediately after 'Detection and Analysis'?
Containment, Eradication and Recovery follows Detection and Analysis. Once an incident is confirmed and understood, the team must limit its spread, remove the cause and restore systems. Lessons-learned review happens afterwards, and preparation is the initial phase of the lifecycle.
- APreparation
- BContainment, Eradication and RecoveryCorrect
- CPost-incident review
- DRisk acceptance
Explanation
The widely used lifecycle runs Preparation, Detection and Analysis, Containment/Eradication/Recovery, and then Post-incident activity. Preparation is the first phase, not the one after detection. The post-incident review occurs only after the incident has been contained and systems restored.
Did you get it right without looking?
One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.
More Cyber Security questions
- During a forensic investigation, an examiner computes a hash value (such as SHA-256) of a seized disk image at acquisition and again before …
- The website of a Chennai online ticketing company becomes unreachable on a sale day because thousands of compromised devices spread across m…
- Under the CERT-In Directions issued in April 2022 under the Information Technology Act, 2000, within what time must a service provider, inte…
- Meera, a company secretary, wants to produce an email printout as evidence in an Indian court. Under the Indian law on electronic records as…
- Ravi receives an email that appears to come from his bank, asking him to click a link and enter his net-banking password to avoid account su…
- In the CIA triad used to describe the objectives of cyber security, what does the 'Integrity' element primarily protect against?