ITPEC FE Morning April 2021 Question 40

Source exam: ITPEC FE Morning April 2021Topic: Security

ITPEC FE Morning April 2021 — Question 40 of 80

Cybersecurity Incident Response Plan — identify phases of an incident response plan.

A cybersecurity incident response plan defines how to detect, respond to, and recover from incidents.

Standard phases (NIST):
- Preparation — policies, tools, training

- Detection & Analysis — identify the incident

- Containment — limit the damage (isolate affected systems)

- Eradication — remove the threat

- Recovery — restore normal operations

- Lessons Learned — post-incident review

Answer: (b) Containment — a core phase of the response plan.

Why not others:
- (a) Attacking systems with scripts — an offensive action, not a response phase

- (c) Social engineering activities — an attack method, not part of the plan

- (d) Stealing user credentials — an attack objective, not a response phase

Key rule: Incident response phases are about defending and recovering, not attacking. If an option describes an offensive action, it's not part of the plan.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.