← Security+: security and production decisions
06 / 7 · 30 MIN

Incidents and controlled response

Coordinate containment, evidence, and recovery according to impact.

Concept and mechanism

An alert is a signal to assess rather than complete proof of incident scope. Correlate sources, identify assets, and decide containment according to evidence, urgency, and authority. With an active threat, waiting for definitive attribution can prolong impact. At the same time, indiscriminately erasing disks can destroy needed information. The runbook should permit proportionate actions and define escalation. Record who decided, what was observed, the action taken, and its service effect. Current NIST SP 800-61r3 integrates preparation and improvement into ongoing risk management alongside response activities.

Guided application

For timelines, preserve original logs and document time zones and clock offsets used in analysis. A summary does not replace evidence. Before closing recovery, address compromised credentials, validate integrity, and monitor recurrence signals; HTTP 200 alone does not prove eradication. When tuning alerts, scope exceptions to justified behavior and test what must remain detectable. For automation, prefer reversible actions when confidence is limited, with defined authority for destructive effects. A playbook needs rehearsal, scope limits, and success criteria to avoid turning false positives into outages.

IN PRACTICE

If EDR and network evidence corroborate malicious activity, use authorized containment and retain feasible evidence. Then confirm the credential used in the attack cannot permit reentry.

Common pitfalls

Demanding absolute certainty before acting; modifying original logs; confusing a new VM with secure recovery; automating destruction with little evidence.

Related topics: Governance, risk, and suppliers · Controls, identity, and cryptography

Take this idea with you

Useful response reduces the threat while retaining reasoning and evidence for subsequent decisions.

Create account

Reference: Incident response and cybersecurity risk management · SY0-701 V7