In the middle of a cyberattack, a security engineer removes the infected devices from the network and locks down all compromised accounts.
In which of the following incident response phases is the security engineer currently operating?
A.
Identification B.
Preparation C.
Lessons learned D.
Eradication E.
Recovery F.
Containment.
F.
In the middle of a cyberattack, a security engineer removes the infected devices from the network and locks down all compromised accounts.
In which of the following incident response phases is the security engineer currently operating?
A.
Identification
B.
Preparation
C.
Lessons learned
D.
Eradication
E.
Recovery
F.
Containment.
F.
The security engineer is currently operating in the Containment phase of the incident response plan.
The incident response plan is a process that outlines the steps to be taken when an incident occurs, including cyberattacks. The six phases of the incident response plan are:
In the given scenario, the security engineer has already identified the cyberattack and is currently taking steps to contain the incident by removing the infected devices from the network and locking down all compromised accounts. The containment phase aims to prevent further damage and minimize the impact of the incident on the organization's operations.
Therefore, the security engineer is currently operating in the Containment phase of the incident response plan.