CREST Incident Response & Forensic Analysis 1 — Questions and Answers
Question 1: What is the first step in incident response?
- Ignoring the incident and waiting.
- Identifying and confirming the incident (Correct answer)
- Informing the public.
- Shutting down the system immediately.
Correct answer: Identifying and confirming the incident
The first and most critical step in incident response is to accurately identify and confirm that an actual security incident has occurred. This involves detecting anomalies, gathering initial evidence, and verifying the nature and scope of the potential breach. Without proper identification, an organization cannot effectively contain, eradicate, or recover from the incident, making this foundational for all subsequent response activities.
What is the first step in incident response?