L14. Incident Response: Detection, Containment & Recovery
Course outlineLesson 14 of 20
Every organization will experience security incidents. The difference between a minor disruption and a major breach often comes down to how quickly and effectively the IR process is executed.
NIST Incident Response Lifecycle (SP 800-61)
The NIST IR lifecycle has six phases:
- Preparation: IR plan, playbooks, contact lists, tooling, tabletop exercises
- Detection & Analysis: identify that an incident has occurred; determine scope and severity
- Containment: stop the spread; short-term (isolate host) then long-term (patch/rebuild)
- Eradication: remove the root cause (malware, compromised accounts, vulnerable software)
- Recovery: restore systems to normal operation; monitor for recurrence
- Post-Incident Activity: lessons learned report; update playbooks; share IOCs
Preparation
Strong preparation is the phase that determines IR success:
- Written IR plan with roles, responsibilities, and escalation paths
- Playbooks for common scenarios (ransomware, data breach, insider threat)
- Pre-authorized forensic tools on standby
- Legal and PR contact lists
- Tabletop exercises (discussion-based drills) to test the plan without real disruption
Containment Strategies
Short-term containment: immediately isolate the affected system (disconnect from network, block at firewall) to stop the spread. Preserve the system for forensics. Long-term containment: apply temporary mitigations (patch, change credentials, block IOCs) while eradication and recovery are planned. Evidence preservation: before wiping/rebuilding, capture a memory dump and disk image. Maintain chain of custody.Recovery and Post-Incident
Recovery involves restoring from known-good backups, monitoring for re-infection, and gradually returning systems to production.
Post-incident lessons learned should capture: what happened, how it was detected, what worked, what failed, and what changes will be made to prevent recurrence. These findings feed back into the Preparation phase.
- ✓NIST IR lifecycle: Preparation, Detection, Containment, Eradication, Recovery, Post-Incident (Lessons Learned)
- ✓Containment comes before eradication: stop the spread first, then remove the root cause
- ✓Tabletop exercises are discussion-based drills that test the IR plan without causing real system disruption
- ✓Chain of custody must be documented for forensic evidence to be admissible in legal proceedings
- ✓Post-incident lessons learned feed back into Preparation: update playbooks, share IOCs, improve controls
1. During an active ransomware incident, a responder disconnects the affected server from the network to stop the spread. Which IR phase is this action part of?
2. A security team conducts a meeting-based exercise where participants walk through a ransomware scenario and discuss their responses without actually activating any systems. What type of exercise is this?
3. After containing a breach, the IR team restores affected systems from the most recent clean backup and monitors them for 30 days. Which IR phase is this?
Recommended: Pluralsight
Turn your CompTIA Security+ concepts into passing marks: Pluralsight adds structured study plans, practice exams, and hands-on scenario labs.