hardMultiple SelectObjective-mapped
CISSP Practice Question: Which THREE of the following are essential…
Which THREE of the following are essential components of an effective incident response plan according to NIST SP 800-61?
⚠ Common exam trap
It's easy for candidates to confuse Notification as a formal phase because it appears in many incident response frameworks (e.g., SANS PICERL), but NIST SP 800-61 does not list it as a core phase; instead, it is a task within other phases.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preparation
NIST SP 800-61 defines the incident response lifecycle as having four phases: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Preparation is the foundational phase that establishes the incident response capability, including creating policies, forming a team, and acquiring necessary tools before any incident occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Preparation
Why this is correct
Preparation is the foundational phase of an incident response plan, establishing the necessary policies, procedures, and resources before an incident occurs. This includes developing communication plans, training personnel, acquiring essential tools, and conducting regular drills to ensure the organization is ready to respond effectively. Proper preparation significantly reduces the impact and duration of security incidents by building a robust framework for action.
- ✗
Notification
Why it's wrong here
While critical for managing stakeholder expectations and compliance, notification is typically a sub-component of the broader 'Communication' or 'Reporting' phase within an incident response plan, rather than a standalone essential phase itself. This step involves informing relevant parties, such as management, legal counsel, customers, or regulatory bodies, about the incident's status and impact. It ensures transparency and adherence to legal obligations but is integrated into the larger incident handling process.
- ✓
Detection and Analysis
Why this is correct
This crucial phase focuses on actively monitoring systems and networks for anomalies and indicators of compromise, then thoroughly investigating potential security incidents. It involves collecting and correlating log data from various sources, performing initial triage, and determining the scope, nature, and severity of the incident. Accurate detection and analysis are vital for initiating an appropriate and timely response, preventing further damage, and guiding subsequent actions.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning is a proactive security measure aimed at identifying weaknesses in systems and applications *before* an attack occurs, making it part of vulnerability management, not an essential component of an incident response plan's *execution phases*. While it contributes significantly to overall security posture and can prevent incidents, it is distinct from the reactive steps taken *during* or *after* an incident has been detected. Incident response focuses on handling actual events, not preventative scanning.
- ✓
Containment, Eradication, and Recovery
Why this is correct
These three sequential actions form the core operational response to an active incident, directly addressing the threat. Containment involves isolating affected systems or networks to prevent further damage or the spread of the incident; eradication focuses on removing the root cause of the incident and any malicious artifacts; and recovery entails restoring systems and data to normal operations, often with enhanced security controls. Successfully executing these steps is paramount to minimizing business disruption and restoring trust.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response lifecycle
The Incident response lifecycle is the structured process organizations follow to detect, contain, eradicate, and recover from cybersecurity incidents while learning from each event to improve future defenses.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.