CBROPS Exam QuestionsBrowse all questions from this exam

CBROPS Exam - Question 261


An engineer is working on a ticket for an incident from the incident management team. A week ago, an external web application was targeted by a DDoS attack. Server resources were exhausted and after two hours, it crashed. An engineer was able to identify the attacker and technique used. Three hours after the attack, the server was restored and the engineer recommended implementing mitigation by Blackhole filtering and transferred the incident ticket back to the IR team. According to NIST.SP800-61, at which phase of the incident response did the engineer finish work?

Show Answer
Correct Answer:

Discussion

2 comments
Sign in to comment
imbatnom
Oct 16, 2024

Is D correct? It seems it may be A.

2c44ebeOption: A
May 4, 2025

Since the engineer restored the server (recovery) and recommended a mitigation for the future (which will be implemented as part of future recovery and preparedness), their direct work in incident response was completed during the Containment, Eradication, and Recovery phase. The responsibility for subsequent actions (implementation of blackhole filtering, post-incident analysis) lies with the incident response team.