A member of the SOC team is checking the dashboard provided by the Cisco Firepower Manager for further Isolation actions. According to NIST SP800-61, in which phase of incident response is this action?
According to NIST SP800-61, the incident response lifecycle consists of four phases: Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity.
When a SOC team member checks the Cisco Firepower Manager dashboard for further isolation actions, they are working within the Eradication and Recovery phase.
This phase focuses on removing the threat from the environment and recovering affected systems to normal operations.
NIST SP800-61 Computer Security Incident Handling Guide
Incident Response Phases Explained
Role of SOC in Incident Response
Kerrie
9 months agoWillard
9 months agoCeleste
10 months agoCarin
10 months agoRonnie
10 months agoRoxane
10 months agoScot
11 months agoEden
11 months agoAhmad
11 months agoHyun
11 months agoLanie
11 months agoVeronika
11 months agoPamella
11 months agoRyann
2 years agoAnnabelle
2 years agoVelda
2 years agoLazaro
2 years agoNieves
2 years agoJean
2 years agoRefugia
2 years agoJeffrey
2 years agoShizue
2 years agoClorinda
2 years agoWilda
2 years agoLuis
2 years agoCatherin
2 years agoElly
2 years agoAn
2 years agoLouisa
2 years agoRosann
2 years agoOna
2 years agoAllene
2 years agoSerita
2 years agoOzell
2 years agoBernadine
2 years agoAgustin
2 years agoTimothy
2 years agoSteffanie
2 years agoRebbecca
2 years agoAudra
2 years ago