Open cardosec

Case ABDCA7 · Blue team / DFIR · L1 Foundations

The Incident Response Lifecycle

Practise as: Explain it · Interview

Interview questionWalk me through the phases of incident response.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. SP 800-61 Rev. 2 phases: Preparation; Detection/Analysis; Containment, Eradication, Recovery; Post-Incident. Rev. 3 maps IR to CSF 2.0.
  2. Preparation means playbooks, logging, contact lists, jump kits and tested backups before anything happens.
  3. Analysis scopes the incident: which hosts, accounts and data, and the initial access vector.
  4. Lessons learned feed back into detections, controls and playbooks; it is a loop, not a line.

If the interviewer pushes back

  • NIST SP 800-61 Rev. 3 realigned IR to CSF 2.0 functions. What changed in how IR is framed?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.