Security controls are designed to reduce the probability and impact of compromise.
They cannot guarantee that security incidents will never occur.
Organizations must therefore be prepared to answer a critical operational question:
When prevention failsβor appears to have failedβwhat happens next?
A mature organization does not improvise incident response after:
ransomware begins encrypting servers;
privileged credentials are stolen;
sensitive information is exfiltrated;
a public application is compromised;
malware spreads across endpoints.
Instead, the organization has already defined:
incident responsibilities;
detection mechanisms;
escalation procedures;
communications;
containment options;
evidence requirements;
recovery procedures;
reporting obligations.
The operational lifecycle can be visualized as:
PREPARE
β
DETECT
β
TRIAGE
β
RESPOND
β
CONTAIN / MITIGATE
β
ERADICATE / REMEDIATE
β
RECOVER
β
LEARN
β
IMPROVE
The current CISSP Examination Outline places this lesson primarily under:
Including:
detection;
response;
mitigation;
reporting;
recovery;
remediation;
lessons learned.
And:
Including:
firewalls;
next-generation firewalls;
web application firewalls;
network firewalls;
IDS and IPS;
whitelisting and blacklisting;
third-party provided security services;
sandboxing;
honeypots and honeynets;
anti-malware;
machine-learning and Artificial Intelligence based tools.
NIST's current incident-response publication is SP 800-61 Rev. 3, finalized in April 2025. Rather than treating incident response as an isolated technical process, Rev. 3 integrates incident response throughout cybersecurity risk management and the six functions of NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, and Recover.
The central Lesson Twenty-Six question is:
When suspicious activity becomes a security incident, how should an organization detect, prioritize, contain, mitigate, remediate, recover, communicate, and learn from the event while maintaining preventive and detective controls that reduce current and future risk?
| Lesson Topic | Primary Alignment |
|---|---|
| Incident management | 7.6 |
| Detection | 7.6 |
| Incident response | 7.6 |
| Mitigation | 7.6 |
| Incident reporting | 7.6 |
| Recovery | 7.6 |
| Remediation | 7.6 |
| Lessons learned | 7.6 |
| Incident preparation | 7.6 supporting concept |
| Incident triage | 7.6 supporting concept |
| Incident classification | 7.6 supporting concept |
| Incident severity | 7.6 supporting concept |
| Escalation | 7.6 supporting concept |
| Containment | 7.6 supporting concept |
| Eradication | 7.6 supporting concept |
| Root-cause analysis | 7.6 |
| Playbooks | 7.6 supporting concept |
| Runbooks | 7.6 supporting concept |
| Incident communications | 7.6 |
| Regulatory notification | 7.6 / Domain 1 |
| Evidence-aware response | 7.1 / 7.6 |
| Firewalls | 7.7 |
| NGFW | 7.7 |
| Network firewall | 7.7 |
| WAF | 7.7 |
| IDS | 7.7 |
| IPS | 7.7 |
| Allowlisting/whitelisting | 7.7 |
| Denylisting/blacklisting | 7.7 |
| Third-party security services | 7.7 |
| Sandboxing | 7.7 |
| Honeypots | 7.7 |
| Honeynets | 7.7 |
| Anti-malware | 7.7 |
| AI/ML security tools | 7.7 |
| EDR concepts | 7.7 supporting concept |
| Detection tuning | 7.2 / 7.7 |
| Prevention-in-depth | 7.7 |
| Tabletop exercise | 7.6 / 7.12 bridge |
| Incident metrics | 7.6 / Domain 6 bridge |
After completing this lesson, you should be able to:
Define incident management.
Distinguish events, alerts, incidents, and crises.
Explain incident-response preparation.
Explain the importance of incident-response governance.
Identify common incident-response stakeholders.
Explain CSIRT/CIRT functions.
Explain incident detection.
Explain alert validation.
Explain incident triage.
Explain incident classification.
Explain incident severity.
Explain incident priority.
Explain escalation.
Explain incident-response activation.
Explain containment.
Distinguish short-term and longer-term containment.
Explain isolation.
Explain mitigation.
Explain eradication.
Explain remediation.
Distinguish mitigation from remediation.
Explain incident recovery.
Explain recovery validation.
Explain monitoring after restoration.
Explain incident reporting.
Explain internal communications.
Explain external communications.
Explain management notification.
Explain legal/privacy involvement.
Explain regulatory notification concepts.
Explain customer and partner communications.
Explain media/public-relations coordination.
Explain evidence-aware incident response.
Explain chain-of-custody concerns during response.
Explain lessons learned.
Explain post-incident review.
Explain root-cause analysis.
Explain corrective actions.
Explain playbooks.
Explain runbooks.
Explain automation in incident response.
Explain tabletop exercises.
Explain incident-response metrics.
Explain time-to-detect concepts.
Explain time-to-contain concepts.
Define network firewall.
Explain firewall policy.
Define NGFW.
Define WAF.
Distinguish WAF from network firewall.
Explain IDS and IPS operational roles.
Explain allowlisting.
Explain denylisting.
Compare allowlisting and denylisting.
Explain third-party security services.
Explain MDR and MSSP concepts.
Explain sandboxing.
Explain honeypots.
Explain honeynets.
Explain deception controls.
Explain anti-malware.
Explain signature-based anti-malware.
Explain behavior-based anti-malware.
Explain endpoint detection concepts.
Explain AI/ML use in detection.
Explain AI/ML limitations.
Explain automation risk.
Explain detection-in-depth.
Explain preventive versus detective controls.
Apply FIRST/BEST/MOST CISSP reasoning to incident-response scenarios.
Incident management is the coordinated process for addressing security incidents from detection through response, recovery, remediation, and organizational learning.
The goal is not simply:
remove malware.
The broader goal is:
protect people, mission, information, systems, reputation, and legal interests while restoring trustworthy operations.
NIST SP 800-61 Rev. 3 explicitly integrates incident response into broader cybersecurity risk management rather than treating it as an isolated emergency activity.
Incident readiness touches all six NIST CSF 2.0 functions:
GOVERN
β
IDENTIFY
β
PROTECT
β
DETECT
β
RESPOND
β
RECOVER
NIST emphasizes that all six functions contribute to incident response.
The worst time to determine:
who has authority;
who calls legal counsel;
how systems are isolated;
how evidence is preserved;
how executives are notified
is:
during the crisis.
policies;
plans;
procedures;
contact lists;
tools;
training;
exercises;
communications arrangements;
vendor escalation paths.
An event is an observable occurrence.
Example:
Administrator logs into a server.
An alert is a notification generated because activity matches defined detection criteria.
Example:
Administrator logs in from an unusual country.
An incident is a security event or collection of events requiring coordinated security response.
Example:
Stolen administrator credentials are used to modify critical systems.
A crisis may have consequences beyond normal incident-management capability.
Examples:
widespread destructive ransomware;
prolonged national-scale outage;
major safety impact.
EVENTS
β
SOME GENERATE ALERTS
β
SOME ALERTS BECOME INCIDENTS
β
SOME INCIDENTS BECOME CRISES
A security tool detecting something unusual does not automatically establish:
confirmed compromise.
Security teams must:
validate;
contextualize;
triage.
Incident-response authority should be established in advance.
The organization needs to know:
Who can make urgent decisions?
isolate production systems;
disable executive accounts;
engage forensic consultants;
notify authorities;
shut down services;
activate disaster recovery.
These decisions may have substantial:
legal;
operational;
financial
consequences.
Organizations may use terms such as:
Computer Security Incident Response Team;
Cybersecurity Incident Response Team;
Incident Response Team.
Depending on incident severity:
SECURITY
β
IT / OPERATIONS
β
LEGAL
β
PRIVACY
β
HR
β
BUSINESS OWNER
β
EXECUTIVE MANAGEMENT
β
COMMUNICATIONS
triage;
technical investigation;
containment;
coordination;
monitoring.
isolate systems;
rebuild servers;
restore applications;
deploy fixes.
legal obligations;
preservation;
law enforcement;
contractual issues;
notification.
Whether affected information includes:
personal information;
regulated data;
and what privacy obligations may apply.
employees;
insider behavior;
disciplinary matters;
personnel records.
May coordinate:
customer statements;
press releases;
stakeholder messaging.
business-risk decisions;
major operational decisions;
resource allocations.
Major incidents benefit from a clearly identified coordinator or incident leader.
The point is:
avoid conflicting commands and fragmented response.
Current ISC2 Objective 7.6 explicitly lists detection as part of incident management.
Detection may originate from:
SIEM;
EDR;
IDS/IPS;
cloud security tools;
users;
third parties;
threat intelligence;
law enforcement.
A user reporting:
βMy MFA prompt appeared when I was not logging inβ
may provide important early warning.
Examples:
bank identifies fraud;
customer reports exposed data;
researcher reports vulnerability;
cloud provider reports abuse.
Triage determines:
Is the alert credible?
What is affected?
How urgent is it?
Who should respond?
ALERT
β
VALIDATE
β
INCIDENT?
ββββ΄ββββ
NO YES
β β
CLOSE CLASSIFY
β
PRIORITIZE
β
ESCALATE
Organizations may classify incidents by:
type;
severity;
affected asset;
data type.
malware;
unauthorized access;
data exposure;
denial of service;
account compromise;
insider event.
Factors may include:
business impact;
asset criticality;
data sensitivity;
scope;
safety;
regulatory impact.
A severe vulnerability affecting:
an isolated test system
may receive different operational priority than:
active compromise of a critical payment system.
IMPACT
+
SCOPE
+
ASSET CRITICALITY
+
DATA SENSITIVITY
+
ACTIVE THREAT
=
INCIDENT PRIORITY
Escalation moves an incident to personnel with:
higher authority;
specialized expertise;
broader responsibility.
Examples:
regulated information affected;
critical production outage;
executive account compromise;
public exposure;
safety risk.
Response includes coordinated actions intended to:
understand;
control;
reduce;
resolve
the incident.
Alert:
Malware detected on one endpoint.
Immediate action:
Shut down the entire enterprise?
Usually not.
First determine:
confidence;
spread;
criticality;
response options.
Containment limits:
the spread or impact of an incident.
isolate endpoint;
disable compromised account;
block malicious domain;
segment affected subnet;
revoke tokens.
Stop:
additional harm.
Example:
COMPROMISED DEVICE
β
NETWORK ISOLATION
May permit business operation while remediation proceeds.
Example:
move workload to isolated network;
block vulnerable interface;
provide limited alternative service.
If investigation matters, deleting or reformatting immediately may:
destroy evidence.
Where appropriate, isolating can stop attacker communications while preserving evidence.
Perfect evidence preservation should not be allowed to create unacceptable:
human;
mission;
safety;
operational
harm.
Mitigation is explicitly listed in CISSP Objective 7.6.
Reduce:
likelihood;
spread;
impact
even if the root cause has not yet been completely eliminated.
Vulnerable remote service cannot immediately be replaced.
Temporary action:
restrict access to approved administration network.
Risk is reduced.
The vulnerability still exists.
Eradication removes:
malicious presence or underlying compromise.
Examples:
remove malware;
eliminate persistence;
disable malicious accounts;
remove unauthorized scheduled tasks.
Remove malware.
But attacker entered through:
unpatched public server.
If server remains vulnerable:
reinfection may occur.
Remediation addresses the condition enabling or resulting from the incident.
Examples:
patch vulnerability;
correct configuration;
rotate compromised credentials;
redesign weak process.
| Mitigation | Remediation |
|---|---|
| Reduce risk | Correct underlying weakness |
| Can be temporary | Intended as corrective resolution |
| Containment-oriented | Root-cause-oriented |
Compromised account:
DISABLE ACCOUNT
β
REVOKE SESSIONS
β
RESET CREDENTIALS
β
INVESTIGATE RELATED ACCESS
β
CORRECT ROOT CAUSE
Recovery restores:
trustworthy business operation.
Recovery is explicitly included in Objective 7.6.
Before restoring production:
malware removed?
vulnerability corrected?
credentials secure?
configuration validated?
logging functional?
ERADICATE
β
REBUILD / RESTORE
β
PATCH / HARDEN
β
VALIDATE
β
RETURN TO SERVICE
β
HEIGHTENED MONITORING
Is the backup from before the compromise?
Restoring a compromised backup can:
restore the attacker.
After restoration, watch for:
recurring malicious connections;
suspicious account activity;
reinfection;
abnormal processes.
Reporting is explicitly included in incident management.
management;
legal;
privacy;
affected business units;
executives.
External reporting may involve:
regulators;
customers;
insurers;
law enforcement;
partners.
Notification obligations depend on:
jurisdiction;
information involved;
industry;
contract.
Coordinate with:
legal;
privacy;
compliance.
Uncoordinated communication can create:
conflicting information;
legal exposure;
reputational harm.
Use an approved communications process.
An analyst should not independently speak to:
the media
simply because the analyst discovered the incident.
Follow approved communications procedures.
discovery;
timeline;
actions;
evidence;
decisions;
communications;
recovery.
coordination;
auditability;
legal response;
lessons learned;
future improvement.
Response actions can change evidence.
Example:
Killing a malicious process changes memory.
Therefore responders should understand:
operational urgency;
evidence impact.
STOP HARM
+
PRESERVE RELEVANT EVIDENCE
+
DOCUMENT ACTIONS
Balance all three.
Lessons learned is explicitly included in CISSP Objective 7.6.
What happened?
Why?
What worked?
What failed?
What should change?
Improve:
controls;
processes;
training;
architecture.
Not:
simply identify someone to punish.
Personnel accountability may matter, but operational learning is broader.
Incident:
Ransomware.
Immediate cause:
Malware executed.
Deeper cause:
Exposed remote service with stolen credential and no MFA.
Root-cause analysis asks:
Why was compromise possible?
LESSON
β
ACTION ITEM
β
OWNER
β
DUE DATE
β
IMPLEMENT
β
VERIFY
If the same incident repeatedly occurs:
lessons learned may not be translating into remediation.
A playbook provides guidance for handling a specific incident class.
Examples:
ransomware;
phishing;
compromised credentials;
lost device.
PHISHING ALERT
β
VALIDATE MESSAGE
β
IDENTIFY RECIPIENTS
β
REMOVE MESSAGE
β
CHECK CLICKS
β
RESET CREDENTIALS IF NEEDED
β
MONITOR
A runbook is often more procedural and task-oriented.
Example:
Exact approved steps to isolate an endpoint in the EDR platform.
| Playbook | Runbook |
|---|---|
| Response strategy/workflow | Specific operational steps |
| Scenario oriented | Task oriented |
| May involve multiple teams | Often technology/process specific |
Terminology varies between organizations.
Automation can perform actions such as:
enrich alerts;
block indicators;
isolate hosts;
create tickets.
Automation can reduce response time for:
repeatable high-confidence actions.
If automation wrongly isolates:
the only production database
availability may be seriously affected.
High-impact automated actions need:
confidence;
safeguards;
approval logic;
recovery.
A tabletop exercise allows stakeholders to discuss how they would respond to a simulated scenario.
Ransomware has disabled 60% of servers and sensitive customer information may have been stolen.
Ask:
Who leads?
Who calls counsel?
Do we shut down?
Who contacts customers?
How do we recover?
roles;
communications;
decision making;
plans;
dependencies.
without requiring:
real production disruption.
detection time;
triage time;
containment time;
recovery time;
recurring incident rate.
Conceptually:
average time between incident occurrence and detection.
MTTR can mean different things:
Mean Time to Respond;
Mean Time to Repair;
Mean Time to Recover;
Mean Time to Remediate.
Always define the metric.
Detection time improved:
8 hours β 20 minutes.
That is useful only if measurement definitions remained consistent.
ISC2 explicitly expects candidates to understand operational use of firewalls, IDS/IPS, allow/deny lists, third-party security services, sandboxing, honeypots/honeynets, anti-malware, and AI/ML-based tools.
Attempts to stop undesirable activity.
Examples:
firewall block;
application allowlist.
Attempts to identify undesirable activity.
Examples:
IDS;
alerting.
Helps restore or correct after an event.
Example:
malware remediation;
system restore.
FIREWALL
β
WAF
β
ENDPOINT PROTECTION
β
IDS / IPS
β
SIEM
β
ANALYST
No single defensive technology is sufficient.
NIST describes firewalls as devices or programs that control network traffic flow between networks or hosts with different security postures.
A firewall can enforce policy based on characteristics such as:
source;
destination;
protocol;
port;
connection state.
stolen credentials;
malicious insiders;
attacks using permitted traffic;
compromised endpoints.
A Next-Generation Firewall commonly combines traditional firewall capabilities with deeper application and threat-aware inspection.
Capabilities may include:
application awareness;
integrated intrusion prevention;
threat detection.
A badly configured NGFW can still permit:
dangerous traffic.
A Web Application Firewall focuses on:
HTTP/HTTPS web application traffic.
malicious request patterns;
application-layer attacks;
suspicious HTTP behavior.
NETWORK FIREWALL
Primarily controls network traffic flows
WAF
Primarily protects web application traffic
A WAF can reduce exposure.
It does not justify leaving:
known application vulnerabilities permanently unfixed.
Primary purpose:
detect and alert.
Can:
detect;
block/prevent.
Incorrect IPS decisions may block:
legitimate business activity.
Therefore tuning matters.
The ISC2 outline currently uses the terms whitelisting/blacklisting.
In this course, the modern synonyms:
allowlisting;
denylisting
will also be used.
Only specifically approved:
applications;
connections;
senders;
actions
are allowed.
APPROVED SOFTWARE
βββ Browser
βββ Office Suite
βββ Business App
EVERYTHING ELSE
β
BLOCK
Execution of:
unknown;
unauthorized
software.
An attacker may misuse:
legitimate administrative tools.
Allowlisting therefore is not sufficient alone.
Specifically identified:
files;
IPs;
domains;
applications
are blocked.
Everything else may remain permitted.
| Allowlisting | Denylisting |
|---|---|
| Permit approved items | Block known prohibited items |
| More restrictive | More flexible |
| Stronger default deny | Requires known bad identification |
| More administrative overhead | Unknown threats may pass |
It depends on:
risk;
environment;
operational need.
However, for highly controlled environments:
default-deny/allowlisting can provide strong protection.
Third-party provided security services are explicitly included in Objective 7.7.
MSSP;
MDR provider;
cloud security monitoring;
DDoS protection;
managed firewall service.
May provide:
monitoring;
firewall management;
vulnerability services;
security operations.
Typically emphasizes:
threat detection;
investigation;
response support.
Exact vendor definitions vary.
The organization remains responsible for:
risk;
governance;
data;
legal obligations.
roles;
response times;
escalation;
evidence;
notification;
data handling;
service availability.
Provider must:
notify organization of critical incident within defined time.
This is a measurable service requirement.
What happens when:
the monitoring provider is unavailable?
Resilience planning still matters.
A sandbox provides an isolated or controlled environment in which suspicious content can be executed or analyzed.
SUSPICIOUS FILE
β
SANDBOX
β
EXECUTE SAFELY
β
OBSERVE BEHAVIOR
β
VERDICT
process creation;
file changes;
network connections;
registry/configuration changes.
detect sandboxing;
delay execution;
behave differently.
Therefore sandboxing provides:
evidence, not certainty.
NIST's glossary describes a honeypot as a system or resource intentionally designed to attract potential intruders.
detection;
research;
deception;
intelligence.
REAL SYSTEMS
β
ATTACKER
β
βΌ
HONEYPOT
Designed to attract suspicious activity
A honeynet extends the concept to:
a network of deceptive or monitored systems.
Low interaction:
limited emulated services.
High interaction:
more realistic environment and richer data.
Higher interaction may create:
greater management and containment risk.
A poorly isolated honeypot may itself be compromised and used to attack:
other systems.
Avoid placing unnecessary sensitive production information in:
deliberately exposed deception systems.
Because legitimate users normally have little reason to access a honeypot:
interaction may be inherently suspicious.
Anti-malware controls attempt to:
identify;
block;
quarantine;
remove
malicious software.
Effective against known malicious patterns.
Can miss:
new;
modified;
obfuscated
malware.
Can look for suspicious actions such as:
mass file encryption;
unusual process injection;
unexpected persistence.
While not separately listed in Objective 7.7, EDR is an important modern operational example of endpoint detection and response technology.
It may provide:
endpoint telemetry;
behavioral detection;
investigation;
host isolation.
Traditional anti-malware often emphasizes:
prevention/detection of malicious software.
EDR additionally emphasizes:
visibility, investigation, and response.
COMPROMISED ENDPOINT
β
EDR ISOLATE
β
MANAGEMENT CHANNEL REMAINS
β
INVESTIGATION / REMEDIATION
Machine-learning and Artificial Intelligence based security tools are explicitly included in current CISSP Objective 7.7.
anomaly detection;
malware classification;
alert correlation;
prioritization;
behavioral analysis.
A model may determine:
β93% suspicious.β
The analyst still needs to understand:
data quality;
false positives;
business context.
poor training data;
bias;
drift;
adversarial manipulation;
unexplained decisions.
If business behavior changes but the model does not adapt:
false positives may increase.
If AI generates:
incident summary
the summary should be validated against:
actual evidence.
Incident conclusions must be based on:
trustworthy evidence.
Not:
model-generated assumptions.
Examples:
disconnect production network;
terminate user;
notify regulator.
Should involve appropriate:
authorized human judgment.
NETWORK FIREWALL
β
NGFW / IPS
β
WAF
β
APPLICATION ALLOWLIST
β
ANTI-MALWARE / EDR
β
MONITORING
Defense in depth reduces dependence on any one layer.
NETWORK TELEMETRY
+
ENDPOINT TELEMETRY
+
IDENTITY EVENTS
+
APPLICATION EVENTS
+
THREAT INTELLIGENCE
=
DETECTION CONTEXT
Firewall allows attack.
But:
EDR detects;
SIEM alerts;
SOC isolates endpoint.
Defense in depth limits impact.
PERFECT ALERT
β
NOBODY RESPONDS
β
INCIDENT CONTINUES
Detection has value only when linked to:
appropriate response.
Organization assumes firewall blocks everything.
Therefore:
no monitoring.
This removes visibility when prevention fails.
INCIDENT
β
WHO IS IN CHARGE?
"UNKNOWN"
LEGAL CONTACT?
"UNKNOWN"
BACKUP STATUS?
"UNKNOWN"
This is why preparation matters.
Use the SierraTec Secure INCIDENT model for incident-management questions.
Determine whether a real incident exists.
Classify severity and establish response authority.
Limit immediate spread and harm.
Understand scope while maintaining evidence integrity.
Eradicate malicious presence and remediate weaknesses.
Restore validated operations.
Communicate according to legal, contractual, operational, and stakeholder requirements.
Implement lessons learned and corrective actions.
I
IDENTIFY
β
βΌ
N
NAME PRIORITY
β
βΌ
C
CONTAIN
β
βΌ
I
INVESTIGATE
β
βΌ
D
DEFEAT ROOT CAUSE
β
βΌ
E
ESTABLISH RECOVERY
β
βΌ
N
NOTIFY
β
βΌ
T
TRANSFORM / LEARN
Use SHIELD for operational detection and preventive controls.
Use appropriate network and application controls.
Restrict unauthorized applications and malicious code.
Use IDS, IPS, EDR, WAF, and analytics.
Add threat and behavioral context.
Tune controls and manage false positives.
Assume any single preventive layer can fail.
S
SEGMENT / FILTER
β
βΌ
H
HARDEN EXECUTION
β
βΌ
I
INSPECT ACTIVITY
β
βΌ
E
ENRICH INTELLIGENCE
β
βΌ
L
LIMIT AUTOMATION RISK
β
βΌ
D
DEFEND IN DEPTH
A SIEM generates a single alert for an unusual login. No other suspicious evidence exists.
What should the analyst do FIRST?
A. Validate and triage the alert.
B. Announce a confirmed breach publicly.
C. Shut down the enterprise.
D. Destroy the endpoint.
A
An alert is an investigative signal, not automatic proof of an incident.
Two incidents occur simultaneously:
malware on an isolated training laptop;
compromised domain administrator credentials being actively used.
Which deserves higher priority?
A. The active domain-administrator compromise.
B. The training laptop because malware always has highest priority.
C. Both must always receive identical priority.
D. Neither.
A
A compromised workstation is actively communicating with a malicious command-and-control server.
What is the BEST immediate action where operationally appropriate?
A. Isolate the workstation while preserving needed investigative capability.
B. Leave the connection active indefinitely.
C. Publicly disclose the user's identity.
D. Delete all logs.
A
A vulnerable application cannot immediately be patched, so access is restricted to a trusted management network.
What is this?
A. Mitigation.
B. Complete remediation.
C. Recovery testing.
D. Evidence destruction.
A
After containing a compromise, the organization patches the exploited vulnerability and rotates stolen credentials.
What activity is MOST clearly represented?
A. Remediation.
B. Detection only.
C. Classification only.
D. Business continuity testing.
A
A compromised production system has been rebuilt.
What should happen before normal operation is fully restored?
A. Validate that remediation, hardening, logging, and security controls are working.
B. Return it immediately without verification.
C. Disable monitoring.
D. Restore old compromised credentials.
A
An incident may involve regulated customer information.
Who should help determine external notification obligations?
A. Appropriate legal, privacy, compliance, and management personnel.
B. Any SOC analyst acting alone.
C. Internet service provider only.
D. Help desk technician alone.
A
A journalist contacts an incident responder directly asking whether the company suffered a breach.
What should the responder do?
A. Follow the organization's authorized communications process.
B. Disclose all technical evidence immediately.
C. Speculate.
D. Publish internal logs.
A
After ransomware recovery, the company returns to normal operations without reviewing why the attack succeeded.
What is the PRIMARY weakness?
A. Lessons learned and corrective improvement were omitted.
B. Recovery should never occur.
C. Logging should be deleted.
D. Malware removal is unnecessary.
A
An attacker repeatedly compromises accounts through legacy authentication.
Resetting passwords stops each incident temporarily.
What is the BEST long-term action?
A. Correct the underlying legacy-authentication exposure.
B. Continue only resetting passwords.
C. Stop monitoring.
D. Ignore repeated incidents.
A
An organization wants to control traffic between an untrusted network and its internal network.
Which control is MOST directly applicable?
A. Network firewall.
B. Honeypot only.
C. Backup system.
D. File-integrity monitor only.
A
A public web application is receiving suspicious HTTP requests targeting application vulnerabilities.
Which control is MOST directly designed for this traffic?
A. WAF.
B. Disk encryption.
C. VPN concentrator.
D. UPS.
A
A highly restricted workstation should execute only five approved applications.
Which control approach BEST supports this?
A. Application allowlisting.
B. Denylisting only.
C. Anonymous execution.
D. Disable endpoint security.
A
Security receives an unknown attachment and wants to observe its behavior without executing it directly on a production endpoint.
Which technique is BEST?
A. Sandboxing.
B. Full production execution.
C. Disable anti-malware.
D. Delete firewall logs.
A
Security creates a decoy server that has no legitimate production users to detect unauthorized interaction.
What control is this?
A. Honeypot.
B. Backup server.
C. Production domain controller.
D. Load balancer.
A
A highly interactive honeypot is connected to the corporate network with unrestricted outbound access.
What is the GREATEST concern?
A. A compromised honeypot could be used to attack other systems.
B. Honeypots cannot be attacked.
C. It automatically encrypts traffic.
D. It replaces incident response.
A
An organization outsources 24/7 monitoring to an MDR provider.
Who remains ultimately responsible for managing organizational security risk?
A. The organization.
B. The MDR provider exclusively.
C. No one.
D. ISP.
A
An AI security tool states that a user is malicious with high confidence.
What is the BEST response?
A. Validate the result using evidence and context before high-impact action.
B. Immediately terminate the user without investigation.
C. Disable all logging.
D. Treat AI output as legally conclusive evidence.
A
A SOAR workflow automatically disables every user whose login produces a location anomaly. Executives traveling internationally are repeatedly locked out.
What needs improvement?
A. Automation logic, confidence thresholds, and contextual safeguards.
B. More automatic disabling.
C. Removal of all human oversight.
D. Deletion of identity logs.
A
A malicious request passes through the network firewall but is blocked by the WAF.
Which concept is demonstrated?
A. Defense in depth.
B. Single point of failure.
C. No security.
D. Media sanitization.
A
No.
Validate and triage.
No.
Response should be:
risk-based and proportionate.
No.
Containment limits damage.
Eradication removes malicious presence.
No.
Mitigation can be temporary.
No.
Validate the recovered environment.
Not necessarily.
The latest backup could contain:
compromise.
No.
Coordinate with:
legal;
privacy;
management;
compliance.
No.
Post-incident learning should feed corrective action.
No.
Still consider:
remediation;
lessons;
reporting;
follow-up.
No.
Allowed traffic and compromised identities can bypass perimeter assumptions.
False.
Advanced controls still require:
policy;
maintenance;
tuning.
No.
It may provide a protective layer, but application vulnerabilities should still be remediated.
Not necessarily.
Inline prevention introduces:
availability risk from incorrect blocks.
Incorrect.
Trusted tools can be used maliciously.
Not necessarily.
Unknown items may not yet be listed.
No.
The organization retains accountability.
No.
Malware may change behavior or evade analysis.
Not ordinarily.
A deception system should not unnecessarily expose real sensitive information.
Incorrect.
A compromised deception environment can become an attack platform.
No.
Use layered endpoint controls.
No.
AI output is:
an analytical signal requiring validation.
No.
Automation must account for:
confidence;
impact;
rollback;
human oversight.
Which CISSP Domain 7 objective addresses incident management?
A. 7.6
B. 7.3
C. 7.12
D. 7.15
A
Which is the BEST distinction between an alert and an incident?
A. An alert is a signal requiring evaluation; an incident requires coordinated security response.
B. They are always identical.
C. Incidents never generate alerts.
D. Alerts are always confirmed attacks.
A
What is triage?
A. Initial validation, classification, and prioritization of suspicious activity.
B. Permanent remediation only.
C. Backup destruction.
D. Media sanitization.
A
What is containment primarily intended to do?
A. Limit incident spread or impact.
B. Prove attacker identity.
C. Replace recovery.
D. Eliminate all logs.
A
What is eradication?
A. Removal of malicious presence and persistence.
B. Initial alert generation.
C. Public communication.
D. Backup retention.
A
What is remediation?
A. Correcting the underlying security weakness.
B. Merely detecting the incident.
C. Temporary isolation only.
D. Ignoring risk.
A
Which activity restores trustworthy operations after an incident?
A. Recovery.
B. Triage.
C. Threat feed collection.
D. Media labeling.
A
Why is heightened monitoring valuable after recovery?
A. It can detect recurrence or incomplete remediation.
B. Monitoring should stop after recovery.
C. It replaces patching.
D. It prevents all future incidents.
A
Who should determine regulatory notification obligations?
A. Appropriate legal/privacy/compliance/management stakeholders.
B. Any analyst alone.
C. Malware vendor.
D. Firewall administrator alone.
A
What is the primary purpose of lessons learned?
A. Improve future security and response capability.
B. Assign blame only.
C. Remove documentation.
D. Disable monitoring.
A
What is a playbook?
A. Scenario-oriented guidance for responding to a defined incident type.
B. Backup hardware.
C. Encryption key.
D. Network protocol.
A
What is a runbook?
A. Detailed operational steps for performing a specific response activity.
B. Business risk appetite.
C. Classification label.
D. Threat actor identity.
A
Which device primarily controls traffic between systems or networks according to security policy?
A. Firewall.
B. UPS.
C. SAN.
D. Printer.
A
Which firewall is specifically focused on protecting web application traffic?
A. WAF.
B. UPS firewall.
C. Backup firewall.
D. HSM.
A
Which technology can actively block detected suspicious network traffic?
A. IPS.
B. IDS only.
C. SIEM only.
D. Honeypot only.
A
What does application allowlisting primarily do?
A. Permit execution of approved applications.
B. Allow every application except known malware.
C. Disable all software.
D. Encrypt memory.
A
What does sandboxing provide?
A. Controlled environment for observing suspicious behavior.
B. Guaranteed malware removal.
C. Physical access control.
D. Data classification.
A
What is a honeypot?
A. Deceptive system or resource designed to attract suspicious interaction.
B. Production backup server.
C. Authentication server.
D. Encryption key store.
A
What is a major limitation of AI-based detection?
A. Output can be inaccurate and requires validation/context.
B. AI has no false positives.
C. AI automatically accepts organizational risk.
D. AI does not require data.
A
Which statement is MOST accurate?
A. Effective incident management combines preparation, detection, response, mitigation, remediation, recovery, reporting, and learning.
B. Incident response is purely technical.
C. Firewalls eliminate the need for incident response.
D. Recovery eliminates the need for lessons learned.
A
Security detects suspicious outbound connections from a critical server, but the evidence is not yet sufficient to confirm compromise.
What should the incident handler do FIRST?
A. Validate and triage the activity while preserving relevant evidence.
B. Publicly announce a breach.
C. Permanently destroy the server.
D. Ignore the activity.
A
An attacker is actively encrypting production file servers. Forensics requests that systems remain online for several hours so memory can be collected.
What should management prioritize?
A. Protect critical operations and contain harm while preserving evidence as safely and practically as possible.
B. Evidence must always take priority over ongoing damage.
C. Do nothing until all evidence is acquired.
D. Delete backups.
A
A compromised endpoint has been isolated, but the attacker still has active cloud sessions using stolen authentication tokens.
What should happen NEXT?
A. Revoke compromised sessions/tokens and continue scope investigation.
B. Assume isolation completely contained the incident.
C. Reconnect the endpoint.
D. Disable logging.
A
Malware has been removed from a server, but the exploited vulnerability remains unpatched.
Which stage is incomplete?
A. Remediation.
B. Detection.
C. Reporting.
D. Classification.
A
A company restores a compromised server from yesterday's backup, but the attacker originally gained access three weeks earlier.
What is the GREATEST concern?
A. The backup may already contain attacker persistence or compromised state.
B. Newer backups are always safe.
C. Restored systems need no validation.
D. Backups eliminate incident investigation.
A
Following a major incident, the organization documents lessons but assigns no owners or due dates to corrective actions.
What is the PRIMARY weakness?
A. Lessons learned are unlikely to produce measurable improvement.
B. Documentation is unnecessary.
C. Root-cause analysis should never create action items.
D. Recovery automatically fixes every weakness.
A
A WAF is blocking attacks against a vulnerable customer application. Management proposes canceling the application's security fix because the WAF appears effective.
What is the BEST response?
A. Treat the WAF as a protective layer while still remediating the underlying application weakness.
B. Never patch applications behind a WAF.
C. A WAF guarantees no compromise.
D. Disable application testing.
A
An IPS begins blocking legitimate customer transactions after a new rule is activated.
What is the BEST action?
A. Investigate and tune or rollback the problematic prevention rule while maintaining appropriate protection.
B. Ignore customer impact.
C. Disable every security control permanently.
D. Treat all blocked customers as attackers.
A
An organization wants strict control over executables on highly sensitive administrative workstations.
Which approach BEST supports this goal?
A. Application allowlisting combined with additional endpoint controls.
B. Denylisting only.
C. No endpoint restrictions.
D. Shared administrator passwords.
A
A honeypot begins making outbound connections to production databases after an attacker compromises it.
What should security conclude?
A. The deception environment lacks sufficient containment and must be isolated.
B. Honeypots should have unrestricted production access.
C. The behavior is normal and should be ignored.
D. Honeypots cannot be compromised.
A
An MDR provider misses a major incident because an organization failed to send cloud identity logs to the provider.
What is the BEST conclusion?
A. Effective third-party monitoring depends on clearly defined telemetry, responsibilities, and integration.
B. The provider automatically has access to every log.
C. Outsourcing eliminates internal governance.
D. Identity logs do not matter.
A
An AI detection system flags thousands of normal activities after a major business-process change.
What should security do?
A. Reevaluate model baselines/tuning and validate alerts against the changed environment.
B. Automatically classify all employees as malicious.
C. Remove all human review.
D. Ignore data quality.
A
An organization has excellent firewalls and endpoint protection but has never practiced an incident-response scenario.
What is the GREATEST concern?
A. Technical controls may not compensate for untested coordination and decision-making processes.
B. Incident response is unnecessary when firewalls exist.
C. Tabletop exercises create vulnerabilities.
D. Security incidents cannot occur.
A
An employee receives an unexpected MFA request and reports it immediately. The SOC discovers password compromise before the attacker successfully authenticates.
What principle does this BEST demonstrate?
A. Human reporting can function as an important detection control.
B. MFA fatigue cannot occur.
C. Users should never report unusual authentication.
D. Incident detection is purely automated.
A
Security notices that the same ransomware entry method has caused three incidents in six months.
What should management prioritize?
A. Root-cause remediation rather than repeatedly performing only containment and recovery.
B. Faster rebuilding only.
C. Stop lessons-learned reviews.
D. Accept recurring compromise as normal.
A
| Phase | Primary Question |
|---|---|
| Preparation | Are we ready? |
| Detection | Did something suspicious happen? |
| Triage | Is it real and how urgent? |
| Containment | How do we limit damage? |
| Eradication | How do we remove malicious presence? |
| Remediation | How do we correct the weakness? |
| Recovery | How do we restore trusted operations? |
| Reporting | Who must know? |
| Lessons Learned | How do we prevent recurrence? |
| Situation | Likely Priority |
|---|---|
| Low-confidence informational alert | Validate |
| Confirmed malware, isolated low-value host | Contain/investigate |
| Active privileged-account takeover | Urgent escalation |
| Active ransomware on critical systems | Major incident/crisis response |
| Sensitive regulated-data exposure | Security + legal/privacy escalation |
| Recurring incident | Root-cause remediation |
| Control | Main Role |
|---|---|
| Network firewall | Control network flows |
| NGFW | Application/threat-aware firewalling |
| WAF | Protect web application traffic |
| IDS | Detect/alert |
| IPS | Detect and block |
| Allowlisting | Permit approved items |
| Denylisting | Block known prohibited items |
| Sandbox | Observe suspicious code safely |
| Honeypot | Deception/detection |
| Honeynet | Network of deceptive systems |
| Anti-malware | Detect/prevent malicious software |
| EDR | Endpoint visibility/detection/response |
| AI/ML | Behavioral/anomaly analysis support |
| Mitigation | Remediation |
|---|---|
| Reduce immediate risk | Correct root weakness |
| Often temporary | Intended as lasting corrective action |
| Example: isolate service | Example: patch vulnerability |
| May preserve business continuity | Removes/reduces cause |
| Stakeholder | Primary Concern |
|---|---|
| Security | Detection, investigation, containment |
| IT Operations | Systems and restoration |
| Legal | Legal obligations and risk |
| Privacy | Personal-data impact |
| HR | Personnel issues |
| Business Owner | Mission/operational impact |
| Executives | Strategic risk decisions |
| Communications | External/internal messaging |
| Third Party | Contracted specialist/support role |
Coordinated handling of security incidents from detection through response, recovery, remediation, and learning.
Notification indicating activity matches defined detection criteria.
Validation, classification, and prioritization of potential incidents.
Assessment of potential or actual incident impact.
Transfer of incident responsibility or awareness to higher authority or specialized personnel.
Actions that limit incident spread or impact.
Separation of compromised or suspicious assets from other systems or communications.
Reduction of incident risk or impact without necessarily removing the underlying cause.
Removal of malicious presence and persistence.
Correction of the underlying vulnerability, configuration, process, or other weakness.
Restoration of validated trustworthy operational capability.
Post-incident review intended to identify improvements and prevent recurrence.
Scenario-oriented incident-response guidance.
Task-oriented operational procedure.
Discussion-based simulation used to test roles, plans, and decision making.
Control that manages network traffic flows according to security policy. NIST's firewall guidance remains SP 800-41 Rev. 1.
Next-Generation Firewall combining network control with deeper application/threat awareness.
Web Application Firewall focused on HTTP/HTTPS application traffic.
Intrusion Detection System.
Intrusion Prevention System.
Permit only explicitly approved items or activity.
Block explicitly prohibited items while permitting others according to policy.
Execution or analysis within an isolated controlled environment.
System or resource intentionally designed to attract potential intruders.
Network of systems designed for deception, monitoring, or attacker observation.
Technology used to identify, block, quarantine, or remove malicious software.
Endpoint Detection and Response.
Managed Detection and Response.
Managed Security Service Provider.
Loss of model accuracy as the environment represented by training/baseline data changes.
Layering multiple complementary security controls so that failure of one does not imply complete security failure.
When facing an incident-management question, use this sequence:
IS IT REALLY AN INCIDENT?
β
WHAT IS THE IMPACT?
β
WHO HAS AUTHORITY?
β
WHAT MUST BE CONTAINED FIRST?
β
WHAT EVIDENCE MUST BE PRESERVED?
β
WHAT CAUSED THE INCIDENT?
β
HOW DO WE REMEDIATE?
β
HOW DO WE RESTORE TRUSTED SERVICE?
β
WHO MUST BE NOTIFIED?
β
WHAT MUST CHANGE AFTERWARD?
When facing a detection/prevention control question:
WHAT ARE WE PROTECTING?
β
WHAT ATTACK PATH EXISTS?
β
DO WE NEED PREVENTION, DETECTION, OR BOTH?
β
WHERE SHOULD THE CONTROL OPERATE?
β
WHAT FALSE-POSITIVE IMPACT EXISTS?
β
HOW WILL WE MONITOR AND TUNE IT?
Remember:
CISSP Domain 7 currently represents 13% of the examination, and Objective 7.6 explicitly includes detection, response, mitigation, reporting, recovery, remediation, and lessons learned.
NIST SP 800-61 Rev. 3 became final in April 2025 and supersedes Rev. 2. It integrates incident response throughout cybersecurity risk management and CSF 2.0.
An event is not automatically an incident.
An alert is not proof of compromise.
Triage validates and prioritizes.
Incident priority should reflect business impact and context.
Containment limits spread.
Eradication removes malicious presence.
Mitigation reduces risk.
Remediation addresses the underlying weakness.
Recovery must restore a trustworthy state.
The newest backup is not necessarily the cleanest backup.
Evidence considerations matter during containment.
Human safety and critical mission protection can outweigh perfect forensic preservation.
Notification requirements depend on legal, regulatory, contractual, and privacy context.
Security analysts should not independently make legal-notification decisions.
Communications should be coordinated.
Lessons learned should create assigned corrective actions.
Repeated incidents suggest inadequate root-cause remediation.
Playbooks provide scenario guidance.
Runbooks provide detailed operational procedures.
Incident-response automation can improve speed but can magnify false-positive consequences.
Tabletop exercises help test decisions and coordination.
Current Objective 7.7 explicitly includes network/next-generation/web application firewalls, IDS/IPS, whitelisting/blacklisting, third-party services, sandboxing, honeypots/honeynets, anti-malware, and AI/ML tools.
Firewalls enforce traffic policy; they do not solve every security problem.
NIST SP 800-41 Rev. 1 remains NIST's final dedicated firewall-policy publication.
WAFs focus on web application traffic.
WAF protection does not remove the obligation to fix vulnerable applications.
IDS primarily detects.
IPS can prevent/block.
IPS false positives can affect availability.
Allowlisting supports default-deny execution models.
Allowlisting does not prevent malicious misuse of approved tools.
Denylisting depends heavily on knowledge of prohibited activity.
Outsourcing operational security does not outsource organizational risk accountability.
Sandboxing provides behavioral evidence, not absolute certainty.
Honeypots are intentionally attractive deception resources.
Deception environments should be isolated sufficiently to prevent attacker pivoting.
Anti-malware should be layered with other endpoint controls.
AI/ML-based detection tools are explicitly part of the current CISSP outline.
AI outputs require evidence-based validation.
High-impact automated response actions require safeguards and human governance.
Defense in depth assumes any single control may fail.
Lesson Twenty-Six connected incident management with the defensive technologies used to prevent, detect, contain, and investigate security threats.
The complete incident-management model is:
PREPARE
β
DETECT
β
TRIAGE
β
CONTAIN
β
INVESTIGATE
β
ERADICATE
β
REMEDIATE
β
RECOVER
β
REPORT
β
LEARN
NIST's current SP 800-61 Rev. 3 treats incident response as part of the broader cybersecurity risk-management lifecycle, with Govern, Identify, Protect, Detect, Respond, and Recover all contributing to effective incident-response capability.
The SierraTec Secure INCIDENT model summarizes the response process:
I β Identify and Validate
N β Name Priority and Owner
C β Contain the Threat
I β Investigate and Preserve Evidence
D β Defeat the Root Cause
E β Establish Trusted Recovery
N β Notify Appropriately
T β Transform Lessons Into Improvement
You learned the essential differences among:
CONTAINMENT
Stop spread
MITIGATION
Reduce risk
ERADICATION
Remove malicious presence
REMEDIATION
Correct the weakness
RECOVERY
Restore trusted operation
You then examined Domain 7.7 defensive technologies.
NETWORK FIREWALL
β
NGFW
β
WAF
β
IDS / IPS
β
ALLOWLISTING
β
ANTI-MALWARE / EDR
β
SANDBOXING
β
DECEPTION
β
AI / ML ANALYTICS
The current ISC2 examination outline explicitly includes these technology categories under operational detection and preventive measures.
You learned that a firewall controls traffic according to policy but does not create complete security. NIST SP 800-41 Rev. 1 remains its final dedicated firewall policy guidance.
You also learned how deception technologies can create strong detection signals. NIST defines a honeypot as a system or resource intentionally designed to attract potential intruders.
Finally, you examined automation and AI.
TELEMETRY
β
ANALYTICS
β
AI / ML
β
RISK SIGNAL
β
HUMAN / AUTOMATED DECISION
β
RESPONSE
AI improves scale and correlation but does not replace:
evidence;
accountability;
human judgment;
risk ownership.
The central Lesson Twenty-Six principle is:
Incident management is not merely a technical cleanup activity. Effective response requires prepared authority, accurate detection, risk-based prioritization, rapid containment, evidence-aware investigation, root-cause remediation, validated recovery, coordinated communications, and continuous improvementβsupported by layered preventive and detective controls that are themselves monitored, tested, and tuned.
Before continuing to Lesson Twenty-Seven, make sure you can explain without reviewing:
What incident management means.
The current CISSP 7.6 incident-management elements.
How NIST SP 800-61 Rev. 3 changed the framing of incident response.
Event versus alert versus incident versus crisis.
Why incident preparation matters.
What a CSIRT/CIRT is.
Why security, IT, legal, privacy, HR, communications, and management may all participate.
Why incident-response authority should be established in advance.
What incident detection means.
What triage means.
How incident classification works.
Severity versus priority.
What escalation means.
What containment does.
Short-term versus longer-term containment.
Why isolation may preserve investigation capability.
Why human safety and mission impact matter during containment.
What mitigation means.
What eradication means.
What remediation means.
Mitigation versus remediation.
What recovery means.
Why recovery requires validation.
Why the latest backup may still be compromised.
Why heightened monitoring should follow recovery.
Why incident reporting requires coordination.
Why legal/privacy personnel may determine external notification requirements.
Why technical personnel should not independently communicate with media.
Why incident documentation matters.
How evidence preservation interacts with response urgency.
What lessons learned means.
Why lessons learned should result in assigned corrective actions.
What root-cause analysis means.
What a playbook is.
What a runbook is.
Playbook versus runbook.
How automation helps incident response.
Why automation can create business disruption.
What tabletop exercises test.
MTTD concept.
Why MTTR must be explicitly defined.
Preventive versus detective versus corrective controls.
What a network firewall does.
What an NGFW adds conceptually.
What a WAF protects.
Network firewall versus WAF.
IDS versus IPS.
Why IPS false positives can affect availability.
What allowlisting means.
What denylisting means.
Allowlisting versus denylisting.
Why trusted applications can still be abused.
What third-party security services are.
MSSP versus MDR conceptually.
Why outsourcing does not transfer risk ownership.
What sandboxing does.
Why malware may evade sandboxes.
What a honeypot is.
What a honeynet is.
Why deception systems need containment.
Why honeypot interaction can provide a high-value detection signal.
What anti-malware does.
Signature versus behavior-based malware detection.
What EDR provides conceptually.
Why EDR is broader than traditional antivirus.
How endpoint isolation can support containment.
How AI and ML may support security operations.
Why AI can generate false positives and incorrect conclusions.
What model drift means.
Why AI-generated incident summaries must be validated.
Why high-impact response decisions require governance.
What defense in depth means operationally.
Why detection without response is insufficient.
Why prevention without monitoring is insufficient.
Lesson Twenty-Seven will continue CISSP Domain 7 and concentrate primarily on Objectives 7.10 through 7.13:
Including:
backup storage strategies;
cloud storage;
onsite and offsite storage;
recovery-site strategies;
cold sites;
hot sites;
resource-capacity agreements;
multiple processing sites;
system resilience;
high availability;
Quality of Service;
fault tolerance.
Including:
response;
personnel;
communications;
assessment;
restoration;
training and awareness;
lessons learned.
Including:
read-through/tabletop;
walkthrough;
simulation;
parallel testing;
full interruption;
stakeholder and regulator communications.
Lesson Twenty-Seven will cover:
backup architecture;
full backups;
incremental backups;
differential backups;
snapshots;
replication;
immutable backups;
offline backups;
the 3-2-1 concept;
backup encryption;
backup integrity;
restoration testing;
RTO;
RPO;
MTD/MAD concepts;
recovery tiers;
cold sites;
warm sites;
hot sites;
reciprocal arrangements;
cloud recovery;
geographic diversity;
high availability;
fault tolerance;
clustering;
redundancy;
failover;
QoS;
Disaster Recovery Plan activation;
emergency communications;
damage assessment;
restoration priorities;
failback;
tabletop exercises;
walkthroughs;
simulations;
parallel tests;
full-interruption tests;
BC versus DR;
business-process continuity;
manual workarounds;
critical dependencies;
supplier continuity;
original SierraTec models;
CISSP exam traps;
knowledge checks;
scenario questions.
The central Lesson Twenty-Seven question will be:
How should an organization design, implement, test, and continuously improve backup, recovery, disaster-recovery, and business-continuity capabilities so critical operations can survive disruption and return to a trusted state within defined business requirements?
This lesson is independently developed educational material for the SierraTec Secure CISSP Certification Preparation Course.
CISSP is administered by ISC2. SierraTec Secure's program is independent certification-preparation material and should not be represented as official ISC2 training unless separately authorized.
The current Domain 7.6 and 7.7 content was verified against the official ISC2 CISSP Certification Exam Outline. Objective 7.6 currently lists detection, response, mitigation, reporting, recovery, remediation, and lessons learned; Objective 7.7 currently lists firewalls, IDS/IPS, whitelisting/blacklisting, third-party security services, sandboxing, honeypots/honeynets, anti-malware, and machine-learning/AI-based tools.
Incident-response material was updated to NIST SP 800-61 Rev. 3, finalized April 3, 2025 and superseding Rev. 2. NIST's current model integrates incident response across cybersecurity risk management and the NIST CSF 2.0 functions.
Firewall concepts were supplemented with NIST SP 800-41 Rev. 1, which remains NIST's final dedicated publication on firewall technologies and firewall policy.
The SierraTec Secure INCIDENT and SHIELD frameworks, diagrams, scenarios, comparisons, knowledge checks, and practice questions are original educational content and are not actual, recalled, leaked, or official CISSP examination questions.