Free PCI Incident Response & Reporting Questions and Answers — Questions and Answers
Question 1: What is the first step in incident response?
- Identification (Correct answer)
- Containment
- Eradication
- Recovery
Correct answer: Identification
The incident response lifecycle begins with identification, which involves detecting and confirming that a security incident has occurred. This initial step is crucial because no further action, such as containment or eradication, can be taken until an incident is recognized. Effective identification relies on monitoring systems, alerts, and user reports.
Question 2: What is the role of the 'containment' phase in incident response?
- Preventing the incident from spreading (Correct answer)
- Investigation of the root cause
- Recovering data from backups
- Publicly disclosing the incident
Correct answer: Preventing the incident from spreading
Once an incident is identified, the containment phase aims to limit the scope and impact of the breach. This involves isolating affected systems, disconnecting networks, or implementing temporary fixes to prevent the incident from spreading further. Effective containment minimizes damage and prevents the incident from escalating into a larger crisis.
What is the first step in incident response?