CGRC Incident Response and Contingency Planning — Questions and Answers
Question 1: According to NIST SP 800-61, which of the following is the CORRECT sequence of phases in an incident response lifecycle?
- Identification → Containment → Eradication → Recovery → Lessons Learned
- Preparation → Detection and Analysis → Containment, Eradication, and Recovery → Post-Incident Activity (Correct answer)
- Triage → Escalation → Remediation → Closure → Documentation
- Discovery → Reporting → Patching → Testing → Verification
Correct answer: Preparation → Detection and Analysis → Containment, Eradication, and Recovery → Post-Incident Activity
NIST SP 800-61 defines four incident response phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity (which includes the lessons-learned process). The other sequences mix elements of different frameworks or incorrectly order the phases.
Question 2: What is the key distinction between a Contingency Plan and a Disaster Recovery Plan (DRP)?
- A Contingency Plan covers all types of disruptions to information systems, while a DRP focuses specifically on recovering IT systems after a major disaster (Correct answer)
- A Contingency Plan is required only for classified systems, while a DRP is required for all federal systems
- A Contingency Plan is developed by the CISO, while a DRP is developed by facilities management
- A Contingency Plan addresses human threats, while a DRP addresses only natural disasters
Correct answer: A Contingency Plan covers all types of disruptions to information systems, while a DRP focuses specifically on recovering IT systems after a major disaster
Per NIST SP 800-34, a Contingency Plan is a broader document covering a range of disruptive events affecting information systems. A Disaster Recovery Plan is a subset that specifically addresses recovery of IT infrastructure following a major disaster. The Contingency Plan may reference or incorporate the DRP.
Question 3: An organization's management states that their critical payroll system must be restored to full operation within 4 hours of a disruption. This requirement is BEST described as which of the following?
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO) (Correct answer)
- Maximum Tolerable Downtime (MTD)
- Mean Time to Repair (MTTR)
Correct answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) defines the maximum acceptable length of time that a system can be offline after a disruption. The RPO defines how much data loss is acceptable (measured in time). MTD is the absolute maximum time a business function can be unavailable before mission failure. MTTR is a reliability metric for average repair time.
Question 4: During a contingency plan test, an organization uses actual production data and physically shuts down the primary data center, requiring IT staff to activate the alternate site. This type of test is BEST described as which of the following?
- Tabletop exercise
- Parallel test
- Full interruption test (Correct answer)
- Structured walk-through
Correct answer: Full interruption test
A full interruption test (also called a full-scale test) involves actually shutting down the primary system and activating the backup/alternate site, making it the most realistic but also most disruptive and risky test type. A parallel test runs both sites simultaneously. A tabletop exercise is discussion-based. A structured walk-through reviews the plan without operational activation.
Question 5: Which NIST Special Publication provides the primary guidance for developing and testing contingency plans for federal information systems?
- NIST SP 800-53
- NIST SP 800-34 (Correct answer)
- NIST SP 800-61
- NIST SP 800-137
Correct answer: NIST SP 800-34
NIST SP 800-34, 'Contingency Planning Guide for Federal Information Systems,' is the primary reference for developing, testing, and maintaining contingency plans. SP 800-53 contains the security control catalog (including CP controls), SP 800-61 covers incident response, and SP 800-137 covers continuous monitoring.
Question 6: After a cybersecurity incident is resolved, an organization conducts a post-incident review. Which of the following outcomes represents the MOST valuable result of this activity from a risk management perspective?
- Determining which employees were responsible for the security failure and documenting it in their personnel files
- Identifying lessons learned that can be used to improve detection capabilities, response procedures, and preventive controls (Correct answer)
- Calculating the total financial cost of the incident for insurance reimbursement purposes
- Confirming that all systems returned to their pre-incident state without any data loss
Correct answer: Identifying lessons learned that can be used to improve detection capabilities, response procedures, and preventive controls
The post-incident activity phase focuses on identifying lessons learned to improve the organization's security posture going forward — updating detection tools, refining response playbooks, and strengthening preventive controls. While cost calculation and system restoration verification are valid activities, the primary risk management value is the organizational learning that reduces likelihood or impact of future incidents.
According to NIST SP 800-61, which of the following is the CORRECT sequence of phases in an incident response lifecycle?