Q: 4
Which are the components of an incident response plan?
Options
Discussion
A . The NIST phases group containment, eradication and recovery into one step, so only A lines up cleanly with that sequence.
Seriously, ISC2 always wants the NIST steps for this. Option A
Guessing C, saw a similar sequence in one of the practice sets, might be overthinking it.
A , had a similar question on a practice test and it matched NIST’s order exactly.
B tbh, had something like this in a mock and that was the answer.
A official guide and practice test questions usually match this sequence. Pretty sure that's what you’d see on the real exam.
I don't think it's C. C looks tempting since it breaks out recovery, but NIST actually combines containment, eradication, and recovery into one phase. So A matches the official framework pretty closely. Sometimes the extra granularity in C can trip folks up, agree?
Not totally sure, maybe A since NIST combines those steps together. But C almost fits if you break them out more.
A , C is a trap since it splits out recovery at the end but NIST lumps those phases together. Seen similar questions on practice tests.
B or C, seen both approaches in practice exams for this. Can't remember which sequence grouped containment and eradication versus split them up.
Be respectful. No spam.
Question 4 of 35