Case ABDCA7 · Blue team / DFIR · L1 Foundations
The Incident Response Lifecycle
Practise as: Explain it · Interview
Interview questionWalk me through the phases of incident response.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- SP 800-61 Rev. 2 phases: Preparation; Detection/Analysis; Containment, Eradication, Recovery; Post-Incident. Rev. 3 maps IR to CSF 2.0.
- Preparation means playbooks, logging, contact lists, jump kits and tested backups before anything happens.
- Analysis scopes the incident: which hosts, accounts and data, and the initial access vector.
- Lessons learned feed back into detections, controls and playbooks; it is a loop, not a line.
If the interviewer pushes back
- NIST SP 800-61 Rev. 3 realigned IR to CSF 2.0 functions. What changed in how IR is framed?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.