A member of the SOC team is checking the dashboard provided by the Cisco Firepower Manager for further isolation actions. According to NIST.SP800-61, in which phase of incident response is this action?
Containment, Eradication, and Recovery
The actions to isolate compromised systems (e.g., using firewalls or tools like Firepower) belong to this phase.
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.200-201 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
2c44ebe
1 month, 1 week ago