Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 200-201 Exam - Topic 4 Question 96 Discussion

A member of the SOC team is checking the dashboard provided by the Cisco Firepower Manager for further Isolation actions. According to NIST SP800-61, in which phase of incident response is this action?
D) The radiation and recovery phase
A) Cost-incident activity phase
B) Preparation phase
C) Selection and analyze phase

Cisco 200-201 Exam - Topic 4 Question 96 Discussion

Actual exam question for Cisco's 200-201 exam
Question #: 96
Topic #: 4
[All 200-201 Questions]

A member of the SOC team is checking the dashboard provided by the Cisco Firepower Manager for further Isolation actions. According to NIST SP800-61, in which phase of incident response is this action?

Show Suggested Answer Hide Answer
Suggested Answer: D

According to NIST SP800-61, the incident response lifecycle consists of four phases: Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity.

When a SOC team member checks the Cisco Firepower Manager dashboard for further isolation actions, they are working within the Eradication and Recovery phase.

This phase focuses on removing the threat from the environment and recovering affected systems to normal operations.


NIST SP800-61 Computer Security Incident Handling Guide

Incident Response Phases Explained

Role of SOC in Incident Response

Contribute your Thoughts:

0/2000 characters
Kerrie
9 months ago
NIST guidelines can be tricky, but I think it's A.
upvoted 0 times
...
Willard
9 months ago
Wait, are we sure it's not the recovery phase?
upvoted 0 times
...
Celeste
10 months ago
Agree, it's all about analyzing the incident!
upvoted 0 times
...
Carin
10 months ago
I thought it was the Preparation phase?
upvoted 0 times
...
Ronnie
10 months ago
It's definitely the Cost-incident activity phase.
upvoted 0 times
...
Roxane
10 months ago
This question reminds me of a practice one we did on incident response phases. I think it’s definitely not the preparation phase, but I’m torn between the cost-incident activity and the recovery phase.
upvoted 0 times
...
Scot
11 months ago
I’m a bit confused here. I thought the preparation phase was more about setting up defenses rather than responding to incidents.
upvoted 0 times
...
Eden
11 months ago
I remember studying the phases, and I feel like checking the dashboard is more about analyzing the situation, so maybe it's the selection and analyze phase?
upvoted 0 times
...
Ahmad
11 months ago
I think this might be related to the containment part of the incident response, which could be in the recovery phase? But I'm not entirely sure.
upvoted 0 times
...
Hyun
11 months ago
Okay, let me see. The SOC team is checking the dashboard and considering further isolation actions, so that sounds like it could be the Containment phase. I'll go with that unless I can think of a better option.
upvoted 0 times
...
Lanie
11 months ago
Hmm, I'm not sure about this one. The phases of incident response can be tricky to remember. I'll have to think through the NIST framework carefully to determine the right answer.
upvoted 0 times
...
Veronika
11 months ago
This question seems straightforward. I think the answer is Containment phase, since the SOC team is taking action to isolate the incident.
upvoted 0 times
...
Pamella
11 months ago
Ugh, I always get the incident response phases mixed up. Is this the Preparation phase or the Containment phase? I need to review those NIST guidelines again before the exam.
upvoted 0 times
...
Ryann
2 years ago
Selection and analyze phase? Nah, that's more like what you'd do after the incident, not during the immediate response.
upvoted 0 times
...
Annabelle
2 years ago
Hope the SOC team isn't trying to 'cost-incident' their way out of this one. That would be a real doozy!
upvoted 0 times
Velda
2 years ago
A: Definitely, rushing into it could make things worse.
upvoted 0 times
...
Lazaro
2 years ago
A: Agreed, rushing into things could make the situation worse.
upvoted 0 times
...
Nieves
2 years ago
B: Yeah, they need to carefully analyze the data before taking any further actions.
upvoted 0 times
...
Jean
2 years ago
B: Yeah, they need to carefully analyze the data before taking any further actions.
upvoted 0 times
...
Refugia
2 years ago
A: I think they are in the Selection and analyze phase.
upvoted 0 times
...
Jeffrey
2 years ago
A: I think they are in the Selection and analyze phase.
upvoted 0 times
...
...
Shizue
2 years ago
I'm going with B) Preparation phase. Monitoring the dashboard is definitely part of getting ready to respond to an incident.
upvoted 0 times
Clorinda
2 years ago
I'm leaning towards D) The radiation and recovery phase. Once we isolate the threat, we need to focus on recovery and preventing future incidents.
upvoted 0 times
...
Wilda
2 years ago
I see your point, but I still think B) Preparation phase is the best fit. We need to be prepared before taking any further actions.
upvoted 0 times
...
Luis
2 years ago
I think it could also be C) Selection and analyze phase. We need to analyze the data on the dashboard to make informed decisions.
upvoted 0 times
...
Catherin
2 years ago
I agree, B) Preparation phase makes sense. It's all about being ready for any incidents.
upvoted 0 times
...
...
Elly
2 years ago
I'm not sure, but I think it could also be D) The radiation and recovery phase, as they are taking actions to isolate and recover from the incident.
upvoted 0 times
...
An
2 years ago
The Radiation and Recovery phase? Really? That sounds more like what you'd do after a nuclear incident, not a cybersecurity event.
upvoted 0 times
Louisa
2 years ago
C: Actually, it's in the Cost-incident activity phase.
upvoted 0 times
...
Rosann
2 years ago
B: No, I believe it's in the Preparation phase.
upvoted 0 times
...
Ona
2 years ago
D: I'm pretty sure it's in the Radiation and Recovery phase.
upvoted 0 times
...
Allene
2 years ago
C: Are you sure? I thought it was in the Cost-incident activity phase.
upvoted 0 times
...
Serita
2 years ago
B: No, I believe it's in the Preparation phase.
upvoted 0 times
...
Ozell
2 years ago
A: I think it's in the Selection and analyze phase.
upvoted 0 times
...
Bernadine
2 years ago
A: I think it's actually in the Selection and analyze phase.
upvoted 0 times
...
...
Agustin
2 years ago
Hmm, this seems to be in the Preparation phase. Checking the dashboard to prepare for further action is a key part of that.
upvoted 0 times
Timothy
2 years ago
I agree, checking the dashboard is crucial for preparing for further actions.
upvoted 0 times
...
Steffanie
2 years ago
Yes, you're right. It's definitely in the Preparation phase.
upvoted 0 times
...
...
Rebbecca
2 years ago
I agree with Audra, because in this phase the SOC team is analyzing the data to make informed decisions.
upvoted 0 times
...
Audra
2 years ago
I think the answer is C) Selection and analyze phase.
upvoted 0 times
...

Save Cancel