Exam 200-201 Topic 4 Question 122 Discussion
Actual exam question for Cisco's 200-201 exam
Question #: 122
Topic #: 4
Question #: 122
Topic #: 4
An engineer discovered a breach, identified the threat's entry point, and removed access. The engineer was able to identify the host, the IP address of the threat actor, and the application the threat actor targeted. What is the next step the engineer should take according to the NIST SP 800-61 Incident handling guide?
Suggested Answer: A Vote an answer
After a breach has been discovered and the immediate threat has been addressed by identifying and removing the threat's access, the next step according to the NIST SP 800-61 Incident Handling Guide is to recover from the threat. This involves restoring systems to normal operation, confirming that the systems are functioning normally, and applying patches or other remediation measures to prevent similar breaches in the future1.
Reference:
Understanding NIST SP 800-61: The Computer Security Incident Handling Guide
Reference:
Understanding NIST SP 800-61: The Computer Security Incident Handling Guide
by Alger at Feb 20, 2025, 04:45 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).