๐Ÿšจ
Critical Skill

Incident Detection & Response

What is an incident, the IR lifecycle (detection through recovery), alert triage, true/false positives.

5
Questions
โ€”
Correct
โ€”
Answered
โ€”
Score
Progress0/5
Start / Continue โ†’
1
Which of the following correctly orders the NIST incident response lifecycle?
โ€”
2
What is a 'true positive' in the context of SIEM alert triage?
โ€”
3
During incident response, what is the primary goal of the Containment phase?
โ€”
4
An analyst receives 200 alerts per day but only 3 are real threats. What problem does this...
โ€”
5
What is the purpose of the Post-Incident Activity (Lessons Learned) phase?
โ€”