CCSK Exam QuestionsBrowse all questions from this exam

CCSK Exam - Question 195


Which phase of the incident response lifecycle includes creating and validating alerts?

Show Answer
Correct Answer: C

The phase of the incident response lifecycle that includes creating and validating alerts is Detection & Analysis. This phase involves identifying potential security incidents through monitoring and alerting mechanisms, and verifying the validity of these alerts to filter out false positives, ensuring that only genuine incidents are escalated for further action.

Discussion

1 comment
Sign in to comment
SHERLOCKAWSOption: C
Jan 5, 2024

Security Guidance v4.0 > p.102 > 9.1.1 Incident Response Lifecycle: • Alerts [endpoint protection, network security monitoring creation, privilege escalation, other indicators of compromise (baseline and anomaly detection), and user behavior analytics • Validate alerts (reducing false positives) and escalation.