Lesson 26: Incident Management and Operational Detection and Prevention

Lesson 27/28 | Study Time: 15 Min

Lesson Twenty-Six

Incident Management and Operational Detection and Prevention

SierraTec Secure CISSP Certification Preparation Course


Lesson Overview

Security controls are designed to reduce the probability and impact of compromise.

They cannot guarantee that security incidents will never occur.

Organizations must therefore be prepared to answer a critical operational question:

When prevention failsβ€”or appears to have failedβ€”what happens next?

A mature organization does not improvise incident response after:

  • ransomware begins encrypting servers;

  • privileged credentials are stolen;

  • sensitive information is exfiltrated;

  • a public application is compromised;

  • malware spreads across endpoints.

Instead, the organization has already defined:

  • incident responsibilities;

  • detection mechanisms;

  • escalation procedures;

  • communications;

  • containment options;

  • evidence requirements;

  • recovery procedures;

  • reporting obligations.

The operational lifecycle can be visualized as:

PREPARE
↓
DETECT
↓
TRIAGE
↓
RESPOND
↓
CONTAIN / MITIGATE
↓
ERADICATE / REMEDIATE
↓
RECOVER
↓
LEARN
↓
IMPROVE

The current CISSP Examination Outline places this lesson primarily under:

Domain 7.6 β€” Conduct Incident Management

Including:

  • detection;

  • response;

  • mitigation;

  • reporting;

  • recovery;

  • remediation;

  • lessons learned.

And:

Domain 7.7 β€” Operate and Maintain Detection and Preventive Measures

Including:

  • firewalls;

  • next-generation firewalls;

  • web application firewalls;

  • network firewalls;

  • IDS and IPS;

  • whitelisting and blacklisting;

  • third-party provided security services;

  • sandboxing;

  • honeypots and honeynets;

  • anti-malware;

  • machine-learning and Artificial Intelligence based tools.

NIST's current incident-response publication is SP 800-61 Rev. 3, finalized in April 2025. Rather than treating incident response as an isolated technical process, Rev. 3 integrates incident response throughout cybersecurity risk management and the six functions of NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, and Recover.

The central Lesson Twenty-Six question is:

When suspicious activity becomes a security incident, how should an organization detect, prioritize, contain, mitigate, remediate, recover, communicate, and learn from the event while maintaining preventive and detective controls that reduce current and future risk?


CISSP Exam Objective Alignment

Lesson TopicPrimary Alignment
Incident management7.6
Detection7.6
Incident response7.6
Mitigation7.6
Incident reporting7.6
Recovery7.6
Remediation7.6
Lessons learned7.6
Incident preparation7.6 supporting concept
Incident triage7.6 supporting concept
Incident classification7.6 supporting concept
Incident severity7.6 supporting concept
Escalation7.6 supporting concept
Containment7.6 supporting concept
Eradication7.6 supporting concept
Root-cause analysis7.6
Playbooks7.6 supporting concept
Runbooks7.6 supporting concept
Incident communications7.6
Regulatory notification7.6 / Domain 1
Evidence-aware response7.1 / 7.6
Firewalls7.7
NGFW7.7
Network firewall7.7
WAF7.7
IDS7.7
IPS7.7
Allowlisting/whitelisting7.7
Denylisting/blacklisting7.7
Third-party security services7.7
Sandboxing7.7
Honeypots7.7
Honeynets7.7
Anti-malware7.7
AI/ML security tools7.7
EDR concepts7.7 supporting concept
Detection tuning7.2 / 7.7
Prevention-in-depth7.7
Tabletop exercise7.6 / 7.12 bridge
Incident metrics7.6 / Domain 6 bridge

Learning Objectives

After completing this lesson, you should be able to:

  1. Define incident management.

  2. Distinguish events, alerts, incidents, and crises.

  3. Explain incident-response preparation.

  4. Explain the importance of incident-response governance.

  5. Identify common incident-response stakeholders.

  6. Explain CSIRT/CIRT functions.

  7. Explain incident detection.

  8. Explain alert validation.

  9. Explain incident triage.

  10. Explain incident classification.

  11. Explain incident severity.

  12. Explain incident priority.

  13. Explain escalation.

  14. Explain incident-response activation.

  15. Explain containment.

  16. Distinguish short-term and longer-term containment.

  17. Explain isolation.

  18. Explain mitigation.

  19. Explain eradication.

  20. Explain remediation.

  21. Distinguish mitigation from remediation.

  22. Explain incident recovery.

  23. Explain recovery validation.

  24. Explain monitoring after restoration.

  25. Explain incident reporting.

  26. Explain internal communications.

  27. Explain external communications.

  28. Explain management notification.

  29. Explain legal/privacy involvement.

  30. Explain regulatory notification concepts.

  31. Explain customer and partner communications.

  32. Explain media/public-relations coordination.

  33. Explain evidence-aware incident response.

  34. Explain chain-of-custody concerns during response.

  35. Explain lessons learned.

  36. Explain post-incident review.

  37. Explain root-cause analysis.

  38. Explain corrective actions.

  39. Explain playbooks.

  40. Explain runbooks.

  41. Explain automation in incident response.

  42. Explain tabletop exercises.

  43. Explain incident-response metrics.

  44. Explain time-to-detect concepts.

  45. Explain time-to-contain concepts.

  46. Define network firewall.

  47. Explain firewall policy.

  48. Define NGFW.

  49. Define WAF.

  50. Distinguish WAF from network firewall.

  51. Explain IDS and IPS operational roles.

  52. Explain allowlisting.

  53. Explain denylisting.

  54. Compare allowlisting and denylisting.

  55. Explain third-party security services.

  56. Explain MDR and MSSP concepts.

  57. Explain sandboxing.

  58. Explain honeypots.

  59. Explain honeynets.

  60. Explain deception controls.

  61. Explain anti-malware.

  62. Explain signature-based anti-malware.

  63. Explain behavior-based anti-malware.

  64. Explain endpoint detection concepts.

  65. Explain AI/ML use in detection.

  66. Explain AI/ML limitations.

  67. Explain automation risk.

  68. Explain detection-in-depth.

  69. Explain preventive versus detective controls.

  70. Apply FIRST/BEST/MOST CISSP reasoning to incident-response scenarios.


Part I β€” Incident Management

1. What Is Incident Management?

Incident management is the coordinated process for addressing security incidents from detection through response, recovery, remediation, and organizational learning.

The goal is not simply:

remove malware.

The broader goal is:

protect people, mission, information, systems, reputation, and legal interests while restoring trustworthy operations.


Part II β€” Incident Response Is Risk Management

2. Current NIST Perspective

NIST SP 800-61 Rev. 3 explicitly integrates incident response into broader cybersecurity risk management rather than treating it as an isolated emergency activity.


3. Six CSF Functions

Incident readiness touches all six NIST CSF 2.0 functions:

GOVERN
↓
IDENTIFY
↓
PROTECT
↓
DETECT
↓
RESPOND
↓
RECOVER

NIST emphasizes that all six functions contribute to incident response.


Part III β€” Preparation Comes Before the Incident

4. The Worst Time to Design Incident Response

The worst time to determine:

  • who has authority;

  • who calls legal counsel;

  • how systems are isolated;

  • how evidence is preserved;

  • how executives are notified

is:

during the crisis.


5. Preparation May Include

  • policies;

  • plans;

  • procedures;

  • contact lists;

  • tools;

  • training;

  • exercises;

  • communications arrangements;

  • vendor escalation paths.


Part IV β€” Event, Alert, Incident, Crisis

6. Event

An event is an observable occurrence.

Example:

Administrator logs into a server.


7. Alert

An alert is a notification generated because activity matches defined detection criteria.

Example:

Administrator logs in from an unusual country.


8. Incident

An incident is a security event or collection of events requiring coordinated security response.

Example:

Stolen administrator credentials are used to modify critical systems.


9. Crisis

A crisis may have consequences beyond normal incident-management capability.

Examples:

  • widespread destructive ransomware;

  • prolonged national-scale outage;

  • major safety impact.


10. Relationship

EVENTS
↓
SOME GENERATE ALERTS
↓
SOME ALERTS BECOME INCIDENTS
↓
SOME INCIDENTS BECOME CRISES

Part V β€” Alert Does Not Equal Incident

11. Critical CISSP Principle

A security tool detecting something unusual does not automatically establish:

confirmed compromise.

Security teams must:

  • validate;

  • contextualize;

  • triage.


Part VI β€” Incident Governance

12. Management Support

Incident-response authority should be established in advance.

The organization needs to know:

Who can make urgent decisions?


13. Potential Decisions

  • isolate production systems;

  • disable executive accounts;

  • engage forensic consultants;

  • notify authorities;

  • shut down services;

  • activate disaster recovery.

These decisions may have substantial:

  • legal;

  • operational;

  • financial

consequences.


Part VII β€” Incident Response Team

14. CSIRT / CIRT

Organizations may use terms such as:

  • Computer Security Incident Response Team;

  • Cybersecurity Incident Response Team;

  • Incident Response Team.


15. Team Composition

Depending on incident severity:

SECURITY
β”‚
IT / OPERATIONS
β”‚
LEGAL
β”‚
PRIVACY
β”‚
HR
β”‚
BUSINESS OWNER
β”‚
EXECUTIVE MANAGEMENT
β”‚
COMMUNICATIONS

Part VIII β€” Security Team

16. Responsibilities May Include

  • triage;

  • technical investigation;

  • containment;

  • coordination;

  • monitoring.


Part IX β€” IT Operations

17. Operations May

  • isolate systems;

  • rebuild servers;

  • restore applications;

  • deploy fixes.


Part X β€” Legal

18. Legal May Advise On

  • legal obligations;

  • preservation;

  • law enforcement;

  • contractual issues;

  • notification.


Part XI β€” Privacy

19. Privacy Personnel May Determine

Whether affected information includes:

  • personal information;

  • regulated data;

and what privacy obligations may apply.


Part XII β€” Human Resources

20. HR May Participate When Incident Involves

  • employees;

  • insider behavior;

  • disciplinary matters;

  • personnel records.


Part XIII β€” Communications

21. Communications Personnel

May coordinate:

  • customer statements;

  • press releases;

  • stakeholder messaging.


Part XIV β€” Executive Management

22. Executives May Make

  • business-risk decisions;

  • major operational decisions;

  • resource allocations.


Part XV β€” Incident Commander

23. Coordination

Major incidents benefit from a clearly identified coordinator or incident leader.

The point is:

avoid conflicting commands and fragmented response.


Part XVI β€” Detection

24. Domain 7.6 Begins With Detection

Current ISC2 Objective 7.6 explicitly lists detection as part of incident management.


25. Incident Sources

Detection may originate from:

  • SIEM;

  • EDR;

  • IDS/IPS;

  • cloud security tools;

  • users;

  • third parties;

  • threat intelligence;

  • law enforcement.


Part XVII β€” User Reports

26. People Are Sensors Too

A user reporting:

β€œMy MFA prompt appeared when I was not logging in”

may provide important early warning.


Part XVIII β€” External Notification

27. Sometimes Others Detect the Incident

Examples:

  • bank identifies fraud;

  • customer reports exposed data;

  • researcher reports vulnerability;

  • cloud provider reports abuse.


Part XIX β€” Triage

28. Triage

Triage determines:

  • Is the alert credible?

  • What is affected?

  • How urgent is it?

  • Who should respond?


Part XX β€” Triage Flow

29.

ALERT
↓
VALIDATE
↓
INCIDENT?
β”Œβ”€β”€β”΄β”€β”€β”€β”
NO YES
β”‚ β”‚
CLOSE CLASSIFY
↓
PRIORITIZE
↓
ESCALATE

Part XXI β€” Incident Classification

30. Classification

Organizations may classify incidents by:

  • type;

  • severity;

  • affected asset;

  • data type.


31. Example Categories

  • malware;

  • unauthorized access;

  • data exposure;

  • denial of service;

  • account compromise;

  • insider event.


Part XXII β€” Severity

32. Severity Should Reflect Risk

Factors may include:

  • business impact;

  • asset criticality;

  • data sensitivity;

  • scope;

  • safety;

  • regulatory impact.


Part XXIII β€” Priority

33. Severity and Priority Can Differ

A severe vulnerability affecting:

an isolated test system

may receive different operational priority than:

active compromise of a critical payment system.


Part XXIV β€” Incident Priority Model

34.

IMPACT
+
SCOPE
+
ASSET CRITICALITY
+
DATA SENSITIVITY
+
ACTIVE THREAT
=
INCIDENT PRIORITY

Part XXV β€” Escalation

35. Escalation

Escalation moves an incident to personnel with:

  • higher authority;

  • specialized expertise;

  • broader responsibility.


36. Escalation Triggers

Examples:

  • regulated information affected;

  • critical production outage;

  • executive account compromise;

  • public exposure;

  • safety risk.


Part XXVI β€” Response

37. Response

Response includes coordinated actions intended to:

  • understand;

  • control;

  • reduce;

  • resolve

the incident.


Part XXVII β€” Do Not Rush Blindly

38. Example

Alert:

Malware detected on one endpoint.

Immediate action:

Shut down the entire enterprise?

Usually not.

First determine:

  • confidence;

  • spread;

  • criticality;

  • response options.


Part XXVIII β€” Containment

39. Containment

Containment limits:

the spread or impact of an incident.


40. Examples

  • isolate endpoint;

  • disable compromised account;

  • block malicious domain;

  • segment affected subnet;

  • revoke tokens.


Part XXIX β€” Short-Term Containment

41. Immediate Goal

Stop:

additional harm.

Example:

COMPROMISED DEVICE
↓
NETWORK ISOLATION

Part XXX β€” Longer-Term Containment

42. Longer-Term Measures

May permit business operation while remediation proceeds.

Example:

  • move workload to isolated network;

  • block vulnerable interface;

  • provide limited alternative service.


Part XXXI β€” Isolation

43. Isolation Is Often Better Than Immediate Destruction

If investigation matters, deleting or reformatting immediately may:

destroy evidence.

Where appropriate, isolating can stop attacker communications while preserving evidence.


Part XXXII β€” But Safety Comes First

44. Lesson Twenty-Four Principle Continues

Perfect evidence preservation should not be allowed to create unacceptable:

  • human;

  • mission;

  • safety;

  • operational

harm.


Part XXXIII β€” Mitigation

45. Current Objective

Mitigation is explicitly listed in CISSP Objective 7.6.


46. Mitigation Means

Reduce:

  • likelihood;

  • spread;

  • impact

even if the root cause has not yet been completely eliminated.


Part XXXIV β€” Mitigation Example

47.

Vulnerable remote service cannot immediately be replaced.

Temporary action:

restrict access to approved administration network.

Risk is reduced.

The vulnerability still exists.


Part XXXV β€” Eradication

48. Eradication

Eradication removes:

malicious presence or underlying compromise.

Examples:

  • remove malware;

  • eliminate persistence;

  • disable malicious accounts;

  • remove unauthorized scheduled tasks.


Part XXXVI β€” Eradication Is Not Enough

49. Example

Remove malware.

But attacker entered through:

unpatched public server.

If server remains vulnerable:

reinfection may occur.


Part XXXVII β€” Remediation

50. Remediation

Remediation addresses the condition enabling or resulting from the incident.

Examples:

  • patch vulnerability;

  • correct configuration;

  • rotate compromised credentials;

  • redesign weak process.


Part XXXVIII β€” Mitigation vs Remediation

51.

MitigationRemediation
Reduce riskCorrect underlying weakness
Can be temporaryIntended as corrective resolution
Containment-orientedRoot-cause-oriented

Part XXXIX β€” Credential Compromise

52. Example

Compromised account:

DISABLE ACCOUNT
↓
REVOKE SESSIONS
↓
RESET CREDENTIALS
↓
INVESTIGATE RELATED ACCESS
↓
CORRECT ROOT CAUSE

Part XL β€” Recovery

53. Recovery

Recovery restores:

trustworthy business operation.


54. Current CISSP Alignment

Recovery is explicitly included in Objective 7.6.


Part XLI β€” Recovery Is Not Simply "Turn It Back On"

55. Trust Must Be Reestablished

Before restoring production:

  • malware removed?

  • vulnerability corrected?

  • credentials secure?

  • configuration validated?

  • logging functional?


Part XLII β€” Recovery Flow

56.

ERADICATE
↓
REBUILD / RESTORE
↓
PATCH / HARDEN
↓
VALIDATE
↓
RETURN TO SERVICE
↓
HEIGHTENED MONITORING

Part XLIII β€” Clean Backup Question

57. Critical Recovery Question

Is the backup from before the compromise?

Restoring a compromised backup can:

restore the attacker.


Part XLIV β€” Recovery Monitoring

58. Heightened Monitoring

After restoration, watch for:

  • recurring malicious connections;

  • suspicious account activity;

  • reinfection;

  • abnormal processes.


Part XLV β€” Reporting

59. Current Objective

Reporting is explicitly included in incident management.


Part XLVI β€” Internal Reporting

60. Internal Reporting Can Include

  • management;

  • legal;

  • privacy;

  • affected business units;

  • executives.


Part XLVII β€” External Reporting

61. Depending on Requirements

External reporting may involve:

  • regulators;

  • customers;

  • insurers;

  • law enforcement;

  • partners.


Part XLVIII β€” Do Not Guess Notification Requirements

62. Important CISSP Principle

Notification obligations depend on:

  • jurisdiction;

  • information involved;

  • industry;

  • contract.

Coordinate with:

  • legal;

  • privacy;

  • compliance.


Part XLIX β€” Single Source of Communications

63. Major Incident

Uncoordinated communication can create:

  • conflicting information;

  • legal exposure;

  • reputational harm.

Use an approved communications process.


Part L β€” Technical Staff and Media

64. Exam Trap

An analyst should not independently speak to:

the media

simply because the analyst discovered the incident.

Follow approved communications procedures.


Part LI β€” Incident Documentation

65. Record

  • discovery;

  • timeline;

  • actions;

  • evidence;

  • decisions;

  • communications;

  • recovery.


Part LII β€” Why Document?

66. Documentation Supports

  • coordination;

  • auditability;

  • legal response;

  • lessons learned;

  • future improvement.


Part LIII β€” Evidence-Aware Incident Response

67. Incident Response and Forensics Intersect

Response actions can change evidence.

Example:

Killing a malicious process changes memory.

Therefore responders should understand:

  • operational urgency;

  • evidence impact.


Part LIV β€” Preserve Where Practical

68.

STOP HARM
+
PRESERVE RELEVANT EVIDENCE
+
DOCUMENT ACTIONS

Balance all three.


Part LV β€” Lessons Learned

69. Current Objective

Lessons learned is explicitly included in CISSP Objective 7.6.


Part LVI β€” Post-Incident Review

70. Questions

  • What happened?

  • Why?

  • What worked?

  • What failed?

  • What should change?


Part LVII β€” Lessons Learned Is Not Blame

71. Mature Goal

Improve:

  • controls;

  • processes;

  • training;

  • architecture.

Not:

simply identify someone to punish.

Personnel accountability may matter, but operational learning is broader.


Part LVIII β€” Root-Cause Analysis

72. Example

Incident:

Ransomware.

Immediate cause:

Malware executed.

Deeper cause:

Exposed remote service with stolen credential and no MFA.

Root-cause analysis asks:

Why was compromise possible?


Part LIX β€” Corrective Actions

73. Lessons Must Become Action

LESSON
↓
ACTION ITEM
↓
OWNER
↓
DUE DATE
↓
IMPLEMENT
↓
VERIFY

Part LX β€” Recurring Incidents

74. Warning Sign

If the same incident repeatedly occurs:

lessons learned may not be translating into remediation.


Part LXI β€” Playbook

75. Incident Playbook

A playbook provides guidance for handling a specific incident class.

Examples:

  • ransomware;

  • phishing;

  • compromised credentials;

  • lost device.


Part LXII β€” Playbook Example

76.

PHISHING ALERT
↓
VALIDATE MESSAGE
↓
IDENTIFY RECIPIENTS
↓
REMOVE MESSAGE
↓
CHECK CLICKS
↓
RESET CREDENTIALS IF NEEDED
↓
MONITOR

Part LXIII β€” Runbook

77. Runbook

A runbook is often more procedural and task-oriented.

Example:

Exact approved steps to isolate an endpoint in the EDR platform.


Part LXIV β€” Playbook vs Runbook

78.

PlaybookRunbook
Response strategy/workflowSpecific operational steps
Scenario orientedTask oriented
May involve multiple teamsOften technology/process specific

Terminology varies between organizations.


Part LXV β€” Automation

79. Security Orchestration

Automation can perform actions such as:

  • enrich alerts;

  • block indicators;

  • isolate hosts;

  • create tickets.


Part LXVI β€” Automation Benefit

80. Speed

Automation can reduce response time for:

repeatable high-confidence actions.


Part LXVII β€” Automation Risk

81. False Positive + Automatic Containment

If automation wrongly isolates:

the only production database

availability may be seriously affected.


82. Governance Principle

High-impact automated actions need:

  • confidence;

  • safeguards;

  • approval logic;

  • recovery.


Part LXVIII β€” Tabletop Exercises

83. Tabletop

A tabletop exercise allows stakeholders to discuss how they would respond to a simulated scenario.


84. Example

Ransomware has disabled 60% of servers and sensitive customer information may have been stolen.

Ask:

  • Who leads?

  • Who calls counsel?

  • Do we shut down?

  • Who contacts customers?

  • How do we recover?


Part LXIX β€” Why Tabletop Exercises Matter

85. They Test

  • roles;

  • communications;

  • decision making;

  • plans;

  • dependencies.

without requiring:

real production disruption.


Part LXX β€” Incident Metrics

86. Metrics Can Include

  • detection time;

  • triage time;

  • containment time;

  • recovery time;

  • recurring incident rate.


Part LXXI β€” MTTD

87. Mean Time to Detect

Conceptually:

average time between incident occurrence and detection.


Part LXXII β€” MTTR Ambiguity

88. Important Exam/Professional Note

MTTR can mean different things:

  • Mean Time to Respond;

  • Mean Time to Repair;

  • Mean Time to Recover;

  • Mean Time to Remediate.

Always define the metric.


Part LXXIII β€” Metrics Need Context

89. Example

Detection time improved:

8 hours β†’ 20 minutes.

That is useful only if measurement definitions remained consistent.


Part LXXIV β€” Detection and Preventive Measures

90. Domain 7.7

ISC2 explicitly expects candidates to understand operational use of firewalls, IDS/IPS, allow/deny lists, third-party security services, sandboxing, honeypots/honeynets, anti-malware, and AI/ML-based tools.


Part LXXV β€” Prevention vs Detection

91. Preventive Control

Attempts to stop undesirable activity.

Examples:

  • firewall block;

  • application allowlist.


92. Detective Control

Attempts to identify undesirable activity.

Examples:

  • IDS;

  • alerting.


93. Corrective Control

Helps restore or correct after an event.

Example:

  • malware remediation;

  • system restore.


Part LXXVI β€” Detection in Depth

94.

FIREWALL
↓
WAF
↓
ENDPOINT PROTECTION
↓
IDS / IPS
↓
SIEM
↓
ANALYST

No single defensive technology is sufficient.


Part LXXVII β€” Network Firewall

95. Firewall

NIST describes firewalls as devices or programs that control network traffic flow between networks or hosts with different security postures.


Part LXXVIII β€” Firewall Purpose

96. Firewall Policy

A firewall can enforce policy based on characteristics such as:

  • source;

  • destination;

  • protocol;

  • port;

  • connection state.


Part LXXIX β€” Firewall Is Not Complete Security

97. A Firewall Does Not Automatically Stop

  • stolen credentials;

  • malicious insiders;

  • attacks using permitted traffic;

  • compromised endpoints.


Part LXXX β€” Next-Generation Firewall

98. NGFW

A Next-Generation Firewall commonly combines traditional firewall capabilities with deeper application and threat-aware inspection.

Capabilities may include:

  • application awareness;

  • integrated intrusion prevention;

  • threat detection.


Part LXXXI β€” NGFW Still Needs Policy

99. Advanced Technology Does Not Replace Governance

A badly configured NGFW can still permit:

dangerous traffic.


Part LXXXII β€” Web Application Firewall

100. WAF

A Web Application Firewall focuses on:

HTTP/HTTPS web application traffic.


Part LXXXIII β€” WAF Use

101. It May Help Detect or Block

  • malicious request patterns;

  • application-layer attacks;

  • suspicious HTTP behavior.


Part LXXXIV β€” WAF vs Network Firewall

102.

NETWORK FIREWALL
Primarily controls network traffic flows

WAF
Primarily protects web application traffic

Part LXXXV β€” WAF Limitation

103. WAF Is Not a Substitute for Secure Code

A WAF can reduce exposure.

It does not justify leaving:

known application vulnerabilities permanently unfixed.


Part LXXXVI β€” IDS Review

104. IDS

Primary purpose:

detect and alert.


Part LXXXVII β€” IPS Review

105. IPS

Can:

  • detect;

  • block/prevent.


Part LXXXVIII β€” Prevention Risk

106. Inline Prevention

Incorrect IPS decisions may block:

legitimate business activity.

Therefore tuning matters.


Part LXXXIX β€” Whitelisting / Allowlisting

107. Terminology

The ISC2 outline currently uses the terms whitelisting/blacklisting.

In this course, the modern synonyms:

  • allowlisting;

  • denylisting

will also be used.


Part XC β€” Allowlisting

108. Allowlist Principle

Only specifically approved:

  • applications;

  • connections;

  • senders;

  • actions

are allowed.


Part XCI β€” Application Allowlisting

109. Example

APPROVED SOFTWARE
β”œβ”€β”€ Browser
β”œβ”€β”€ Office Suite
└── Business App

EVERYTHING ELSE
↓
BLOCK

Part XCII β€” Allowlisting Strength

110. It Can Reduce

Execution of:

  • unknown;

  • unauthorized

software.


Part XCIII β€” Allowlisting Limitation

111. Approved Software Can Still Be Abused

An attacker may misuse:

legitimate administrative tools.

Allowlisting therefore is not sufficient alone.


Part XCIV β€” Denylisting

112. Denylist

Specifically identified:

  • files;

  • IPs;

  • domains;

  • applications

are blocked.

Everything else may remain permitted.


Part XCV β€” Allowlisting vs Denylisting

113.

AllowlistingDenylisting
Permit approved itemsBlock known prohibited items
More restrictiveMore flexible
Stronger default denyRequires known bad identification
More administrative overheadUnknown threats may pass

Part XCVI β€” Which Is Better?

114. CISSP Answer

It depends on:

  • risk;

  • environment;

  • operational need.

However, for highly controlled environments:

default-deny/allowlisting can provide strong protection.


Part XCVII β€” Third-Party Security Services

115. Current Objective

Third-party provided security services are explicitly included in Objective 7.7.


Part XCVIII β€” Examples

116.

  • MSSP;

  • MDR provider;

  • cloud security monitoring;

  • DDoS protection;

  • managed firewall service.


Part XCIX β€” MSSP

117. Managed Security Service Provider

May provide:

  • monitoring;

  • firewall management;

  • vulnerability services;

  • security operations.


Part C β€” MDR

118. Managed Detection and Response

Typically emphasizes:

  • threat detection;

  • investigation;

  • response support.

Exact vendor definitions vary.


Part CI β€” Outsourcing Does Not Outsource Accountability

119. Critical CISSP Principle

The organization remains responsible for:

  • risk;

  • governance;

  • data;

  • legal obligations.


Part CII β€” Provider Requirements

120. Contracts Should Address

  • roles;

  • response times;

  • escalation;

  • evidence;

  • notification;

  • data handling;

  • service availability.


Part CIII β€” SLA

121. Example

Provider must:

notify organization of critical incident within defined time.

This is a measurable service requirement.


Part CIV β€” Third-Party Dependency

122. Question

What happens when:

the monitoring provider is unavailable?

Resilience planning still matters.


Part CV β€” Sandboxing

123. Sandbox

A sandbox provides an isolated or controlled environment in which suspicious content can be executed or analyzed.


Part CVI β€” Example

124.

SUSPICIOUS FILE
↓
SANDBOX
↓
EXECUTE SAFELY
↓
OBSERVE BEHAVIOR
↓
VERDICT

Part CVII β€” Sandbox Observations

125. It May Observe

  • process creation;

  • file changes;

  • network connections;

  • registry/configuration changes.


Part CVIII β€” Sandbox Limitation

126. Sophisticated Malware May

  • detect sandboxing;

  • delay execution;

  • behave differently.

Therefore sandboxing provides:

evidence, not certainty.


Part CIX β€” Honeypot

127. Honeypot

NIST's glossary describes a honeypot as a system or resource intentionally designed to attract potential intruders.


Part CX β€” Purpose

128. Honeypots Can Support

  • detection;

  • research;

  • deception;

  • intelligence.


Part CXI β€” Basic Concept

129.

REAL SYSTEMS

β”‚
ATTACKER
β”‚
β–Ό
HONEYPOT
Designed to attract suspicious activity

Part CXII β€” Honeynet

130. Honeynet

A honeynet extends the concept to:

a network of deceptive or monitored systems.


Part CXIII β€” High-Interaction vs Low-Interaction

131. Conceptually

Low interaction:

limited emulated services.

High interaction:

more realistic environment and richer data.

Higher interaction may create:

greater management and containment risk.


Part CXIV β€” Honeypot Risk

132. Important

A poorly isolated honeypot may itself be compromised and used to attack:

other systems.


Part CXV β€” Production Data

133. Deception Environment

Avoid placing unnecessary sensitive production information in:

deliberately exposed deception systems.


Part CXVI β€” Honeypot Interpretation

134. High Signal

Because legitimate users normally have little reason to access a honeypot:

interaction may be inherently suspicious.


Part CXVII β€” Anti-Malware

135. Anti-Malware

Anti-malware controls attempt to:

  • identify;

  • block;

  • quarantine;

  • remove

malicious software.


Part CXVIII β€” Signature-Based Anti-Malware

136. Strength

Effective against known malicious patterns.


137. Weakness

Can miss:

  • new;

  • modified;

  • obfuscated

malware.


Part CXIX β€” Behavior-Based Anti-Malware

138. Behavior

Can look for suspicious actions such as:

  • mass file encryption;

  • unusual process injection;

  • unexpected persistence.


Part CXX β€” EDR

139. Endpoint Detection and Response

While not separately listed in Objective 7.7, EDR is an important modern operational example of endpoint detection and response technology.

It may provide:

  • endpoint telemetry;

  • behavioral detection;

  • investigation;

  • host isolation.


Part CXXI β€” EDR Is Not Antivirus Only

140. Difference

Traditional anti-malware often emphasizes:

prevention/detection of malicious software.

EDR additionally emphasizes:

visibility, investigation, and response.


Part CXXII β€” Endpoint Isolation

141.

COMPROMISED ENDPOINT
↓
EDR ISOLATE
↓
MANAGEMENT CHANNEL REMAINS
↓
INVESTIGATION / REMEDIATION

Part CXXIII β€” AI and ML Tools

142. Current Exam Alignment

Machine-learning and Artificial Intelligence based security tools are explicitly included in current CISSP Objective 7.7.


Part CXXIV β€” AI/ML Uses

143. Possible Uses

  • anomaly detection;

  • malware classification;

  • alert correlation;

  • prioritization;

  • behavioral analysis.


Part CXXV β€” AI Does Not Equal Intelligence Without Context

144. Model Output

A model may determine:

β€œ93% suspicious.”

The analyst still needs to understand:

  • data quality;

  • false positives;

  • business context.


Part CXXVI β€” Model Risk

145. AI/ML Systems Can Suffer From

  • poor training data;

  • bias;

  • drift;

  • adversarial manipulation;

  • unexplained decisions.


Part CXXVII β€” Model Drift

146. Normal Behavior Changes

If business behavior changes but the model does not adapt:

false positives may increase.


Part CXXVIII β€” AI Hallucination / Incorrect Output

147. Generative AI Assistance

If AI generates:

incident summary

the summary should be validated against:

actual evidence.


Part CXXIX β€” Never Let AI Invent Evidence

148. Critical Principle

Incident conclusions must be based on:

trustworthy evidence.

Not:

model-generated assumptions.


Part CXXX β€” Human Oversight

149. Higher-Impact Decisions

Examples:

  • disconnect production network;

  • terminate user;

  • notify regulator.

Should involve appropriate:

authorized human judgment.


Part CXXXI β€” Preventive Control Layers

150.

NETWORK FIREWALL
↓
NGFW / IPS
↓
WAF
↓
APPLICATION ALLOWLIST
↓
ANTI-MALWARE / EDR
↓
MONITORING

Defense in depth reduces dependence on any one layer.


Part CXXXII β€” Detection Control Layers

151.

NETWORK TELEMETRY
+
ENDPOINT TELEMETRY
+
IDENTITY EVENTS
+
APPLICATION EVENTS
+
THREAT INTELLIGENCE
=
DETECTION CONTEXT

Part CXXXIII β€” Prevention Failure Does Not Mean Total Failure

152. Example

Firewall allows attack.

But:

  • EDR detects;

  • SIEM alerts;

  • SOC isolates endpoint.

Defense in depth limits impact.


Part CXXXIV β€” Detection Without Response

153. Weak Security Program

PERFECT ALERT
↓
NOBODY RESPONDS
↓
INCIDENT CONTINUES

Detection has value only when linked to:

appropriate response.


Part CXXXV β€” Prevention Without Monitoring

154. Weak Model

Organization assumes firewall blocks everything.

Therefore:

no monitoring.

This removes visibility when prevention fails.


Part CXXXVI β€” Response Without Preparation

155.

INCIDENT
↓
WHO IS IN CHARGE?
"UNKNOWN"

LEGAL CONTACT?
"UNKNOWN"

BACKUP STATUS?
"UNKNOWN"

This is why preparation matters.


Part CXXXVII β€” SierraTec Secure INCIDENT Model

156. INCIDENT

Use the SierraTec Secure INCIDENT model for incident-management questions.

I β€” Identify and Validate

Determine whether a real incident exists.

N β€” Name the Priority and Owner

Classify severity and establish response authority.

C β€” Contain the Threat

Limit immediate spread and harm.

I β€” Investigate and Preserve Evidence

Understand scope while maintaining evidence integrity.

D β€” Defeat the Root Cause

Eradicate malicious presence and remediate weaknesses.

E β€” Establish Trusted Recovery

Restore validated operations.

N β€” Notify Appropriately

Communicate according to legal, contractual, operational, and stakeholder requirements.

T β€” Transform Lessons Into Improvement

Implement lessons learned and corrective actions.


Part CXXXVIII β€” INCIDENT Diagram

157.

I
IDENTIFY
β”‚
β–Ό
N
NAME PRIORITY
β”‚
β–Ό
C
CONTAIN
β”‚
β–Ό
I
INVESTIGATE
β”‚
β–Ό
D
DEFEAT ROOT CAUSE
β”‚
β–Ό
E
ESTABLISH RECOVERY
β”‚
β–Ό
N
NOTIFY
β”‚
β–Ό
T
TRANSFORM / LEARN

Part CXXXIX β€” SierraTec Secure SHIELD Model

158. SHIELD

Use SHIELD for operational detection and preventive controls.

S β€” Segment and Filter

Use appropriate network and application controls.

H β€” Harden Execution

Restrict unauthorized applications and malicious code.

I β€” Inspect Activity

Use IDS, IPS, EDR, WAF, and analytics.

E β€” Enrich With Intelligence

Add threat and behavioral context.

L β€” Limit Automated Risk

Tune controls and manage false positives.

D β€” Detect Failure and Defend in Depth

Assume any single preventive layer can fail.


Part CXL β€” SHIELD Diagram

159.

S
SEGMENT / FILTER
β”‚
β–Ό
H
HARDEN EXECUTION
β”‚
β–Ό
I
INSPECT ACTIVITY
β”‚
β–Ό
E
ENRICH INTELLIGENCE
β”‚
β–Ό
L
LIMIT AUTOMATION RISK
β”‚
β–Ό
D
DEFEND IN DEPTH

Part CXLI β€” Worked Scenario 1: Alert vs Incident

160.

A SIEM generates a single alert for an unusual login. No other suspicious evidence exists.

What should the analyst do FIRST?

A. Validate and triage the alert.

B. Announce a confirmed breach publicly.

C. Shut down the enterprise.

D. Destroy the endpoint.

Correct Answer

A

Rationale

An alert is an investigative signal, not automatic proof of an incident.


Part CXLII β€” Scenario 2: Incident Priority

161.

Two incidents occur simultaneously:

  • malware on an isolated training laptop;

  • compromised domain administrator credentials being actively used.

Which deserves higher priority?

A. The active domain-administrator compromise.

B. The training laptop because malware always has highest priority.

C. Both must always receive identical priority.

D. Neither.

Correct Answer

A


Part CXLIII β€” Scenario 3: Containment

162.

A compromised workstation is actively communicating with a malicious command-and-control server.

What is the BEST immediate action where operationally appropriate?

A. Isolate the workstation while preserving needed investigative capability.

B. Leave the connection active indefinitely.

C. Publicly disclose the user's identity.

D. Delete all logs.

Correct Answer

A


Part CXLIV β€” Scenario 4: Mitigation vs Remediation

163.

A vulnerable application cannot immediately be patched, so access is restricted to a trusted management network.

What is this?

A. Mitigation.

B. Complete remediation.

C. Recovery testing.

D. Evidence destruction.

Correct Answer

A


Part CXLV β€” Scenario 5: Remediation

164.

After containing a compromise, the organization patches the exploited vulnerability and rotates stolen credentials.

What activity is MOST clearly represented?

A. Remediation.

B. Detection only.

C. Classification only.

D. Business continuity testing.

Correct Answer

A


Part CXLVI β€” Scenario 6: Recovery

165.

A compromised production system has been rebuilt.

What should happen before normal operation is fully restored?

A. Validate that remediation, hardening, logging, and security controls are working.

B. Return it immediately without verification.

C. Disable monitoring.

D. Restore old compromised credentials.

Correct Answer

A


Part CXLVII β€” Scenario 7: Reporting

166.

An incident may involve regulated customer information.

Who should help determine external notification obligations?

A. Appropriate legal, privacy, compliance, and management personnel.

B. Any SOC analyst acting alone.

C. Internet service provider only.

D. Help desk technician alone.

Correct Answer

A


Part CXLVIII β€” Scenario 8: Media Communication

167.

A journalist contacts an incident responder directly asking whether the company suffered a breach.

What should the responder do?

A. Follow the organization's authorized communications process.

B. Disclose all technical evidence immediately.

C. Speculate.

D. Publish internal logs.

Correct Answer

A


Part CXLIX β€” Scenario 9: Lessons Learned

168.

After ransomware recovery, the company returns to normal operations without reviewing why the attack succeeded.

What is the PRIMARY weakness?

A. Lessons learned and corrective improvement were omitted.

B. Recovery should never occur.

C. Logging should be deleted.

D. Malware removal is unnecessary.

Correct Answer

A


Part CL β€” Scenario 10: Root Cause

169.

An attacker repeatedly compromises accounts through legacy authentication.

Resetting passwords stops each incident temporarily.

What is the BEST long-term action?

A. Correct the underlying legacy-authentication exposure.

B. Continue only resetting passwords.

C. Stop monitoring.

D. Ignore repeated incidents.

Correct Answer

A


Part CLI β€” Scenario 11: Firewall

170.

An organization wants to control traffic between an untrusted network and its internal network.

Which control is MOST directly applicable?

A. Network firewall.

B. Honeypot only.

C. Backup system.

D. File-integrity monitor only.

Correct Answer

A


Part CLII β€” Scenario 12: WAF

171.

A public web application is receiving suspicious HTTP requests targeting application vulnerabilities.

Which control is MOST directly designed for this traffic?

A. WAF.

B. Disk encryption.

C. VPN concentrator.

D. UPS.

Correct Answer

A


Part CLIII β€” Scenario 13: Allowlisting

172.

A highly restricted workstation should execute only five approved applications.

Which control approach BEST supports this?

A. Application allowlisting.

B. Denylisting only.

C. Anonymous execution.

D. Disable endpoint security.

Correct Answer

A


Part CLIV β€” Scenario 14: Sandboxing

173.

Security receives an unknown attachment and wants to observe its behavior without executing it directly on a production endpoint.

Which technique is BEST?

A. Sandboxing.

B. Full production execution.

C. Disable anti-malware.

D. Delete firewall logs.

Correct Answer

A


Part CLV β€” Scenario 15: Honeypot

174.

Security creates a decoy server that has no legitimate production users to detect unauthorized interaction.

What control is this?

A. Honeypot.

B. Backup server.

C. Production domain controller.

D. Load balancer.

Correct Answer

A


Part CLVI β€” Scenario 16: Honeypot Risk

175.

A highly interactive honeypot is connected to the corporate network with unrestricted outbound access.

What is the GREATEST concern?

A. A compromised honeypot could be used to attack other systems.

B. Honeypots cannot be attacked.

C. It automatically encrypts traffic.

D. It replaces incident response.

Correct Answer

A


Part CLVII β€” Scenario 17: Third-Party Service

176.

An organization outsources 24/7 monitoring to an MDR provider.

Who remains ultimately responsible for managing organizational security risk?

A. The organization.

B. The MDR provider exclusively.

C. No one.

D. ISP.

Correct Answer

A


Part CLVIII β€” Scenario 18: AI Detection

177.

An AI security tool states that a user is malicious with high confidence.

What is the BEST response?

A. Validate the result using evidence and context before high-impact action.

B. Immediately terminate the user without investigation.

C. Disable all logging.

D. Treat AI output as legally conclusive evidence.

Correct Answer

A


Part CLIX β€” Scenario 19: Automation

178.

A SOAR workflow automatically disables every user whose login produces a location anomaly. Executives traveling internationally are repeatedly locked out.

What needs improvement?

A. Automation logic, confidence thresholds, and contextual safeguards.

B. More automatic disabling.

C. Removal of all human oversight.

D. Deletion of identity logs.

Correct Answer

A


Part CLX β€” Scenario 20: Defense in Depth

179.

A malicious request passes through the network firewall but is blocked by the WAF.

Which concept is demonstrated?

A. Defense in depth.

B. Single point of failure.

C. No security.

D. Media sanitization.

Correct Answer

A


Part CLXI β€” Common CISSP Exam Traps

180. Trap β€” Every Alert Is an Incident

No.

Validate and triage.


181. Trap β€” Every Incident Requires Shutting Down Everything

No.

Response should be:

risk-based and proportionate.


182. Trap β€” Containment Means Eradication

No.

Containment limits damage.

Eradication removes malicious presence.


183. Trap β€” Mitigation Means Permanent Fix

No.

Mitigation can be temporary.


184. Trap β€” Recovery Means System Is Safe

No.

Validate the recovered environment.


185. Trap β€” Restore the Most Recent Backup Automatically

Not necessarily.

The latest backup could contain:

compromise.


186. Trap β€” Security Team Determines Legal Notification Alone

No.

Coordinate with:

  • legal;

  • privacy;

  • management;

  • compliance.


187. Trap β€” Lessons Learned Can Wait Forever

No.

Post-incident learning should feed corrective action.


188. Trap β€” Incident Response Ends When Service Returns

No.

Still consider:

  • remediation;

  • lessons;

  • reporting;

  • follow-up.


189. Trap β€” Firewall Stops All Attacks

No.

Allowed traffic and compromised identities can bypass perimeter assumptions.


190. Trap β€” NGFW Does Not Need Configuration

False.

Advanced controls still require:

  • policy;

  • maintenance;

  • tuning.


191. Trap β€” WAF Fixes Vulnerable Source Code

No.

It may provide a protective layer, but application vulnerabilities should still be remediated.


192. Trap β€” IPS Is Always Better Than IDS

Not necessarily.

Inline prevention introduces:

availability risk from incorrect blocks.


193. Trap β€” Allowlisting Means Approved Applications Cannot Be Abused

Incorrect.

Trusted tools can be used maliciously.


194. Trap β€” Denylisting Stops Unknown Malware

Not necessarily.

Unknown items may not yet be listed.


195. Trap β€” Outsourced Security Means Outsourced Risk Ownership

No.

The organization retains accountability.


196. Trap β€” Sandbox Verdict Is Perfect

No.

Malware may change behavior or evade analysis.


197. Trap β€” Honeypot Should Contain Real Sensitive Data

Not ordinarily.

A deception system should not unnecessarily expose real sensitive information.


198. Trap β€” Honeypot Needs No Isolation

Incorrect.

A compromised deception environment can become an attack platform.


199. Trap β€” Anti-Malware Equals Complete Endpoint Security

No.

Use layered endpoint controls.


200. Trap β€” AI Output Is Evidence of Guilt

No.

AI output is:

an analytical signal requiring validation.


201. Trap β€” Maximum Automation Is Always Best

No.

Automation must account for:

  • confidence;

  • impact;

  • rollback;

  • human oversight.


Part CLXII β€” Knowledge Check

202. Question 1

Which CISSP Domain 7 objective addresses incident management?

A. 7.6
B. 7.3
C. 7.12
D. 7.15

Correct Answer

A


203. Question 2

Which is the BEST distinction between an alert and an incident?

A. An alert is a signal requiring evaluation; an incident requires coordinated security response.

B. They are always identical.

C. Incidents never generate alerts.

D. Alerts are always confirmed attacks.

Correct Answer

A


204. Question 3

What is triage?

A. Initial validation, classification, and prioritization of suspicious activity.

B. Permanent remediation only.

C. Backup destruction.

D. Media sanitization.

Correct Answer

A


205. Question 4

What is containment primarily intended to do?

A. Limit incident spread or impact.

B. Prove attacker identity.

C. Replace recovery.

D. Eliminate all logs.

Correct Answer

A


206. Question 5

What is eradication?

A. Removal of malicious presence and persistence.

B. Initial alert generation.

C. Public communication.

D. Backup retention.

Correct Answer

A


207. Question 6

What is remediation?

A. Correcting the underlying security weakness.

B. Merely detecting the incident.

C. Temporary isolation only.

D. Ignoring risk.

Correct Answer

A


208. Question 7

Which activity restores trustworthy operations after an incident?

A. Recovery.

B. Triage.

C. Threat feed collection.

D. Media labeling.

Correct Answer

A


209. Question 8

Why is heightened monitoring valuable after recovery?

A. It can detect recurrence or incomplete remediation.

B. Monitoring should stop after recovery.

C. It replaces patching.

D. It prevents all future incidents.

Correct Answer

A


210. Question 9

Who should determine regulatory notification obligations?

A. Appropriate legal/privacy/compliance/management stakeholders.

B. Any analyst alone.

C. Malware vendor.

D. Firewall administrator alone.

Correct Answer

A


211. Question 10

What is the primary purpose of lessons learned?

A. Improve future security and response capability.

B. Assign blame only.

C. Remove documentation.

D. Disable monitoring.

Correct Answer

A


212. Question 11

What is a playbook?

A. Scenario-oriented guidance for responding to a defined incident type.

B. Backup hardware.

C. Encryption key.

D. Network protocol.

Correct Answer

A


213. Question 12

What is a runbook?

A. Detailed operational steps for performing a specific response activity.

B. Business risk appetite.

C. Classification label.

D. Threat actor identity.

Correct Answer

A


214. Question 13

Which device primarily controls traffic between systems or networks according to security policy?

A. Firewall.

B. UPS.

C. SAN.

D. Printer.

Correct Answer

A


215. Question 14

Which firewall is specifically focused on protecting web application traffic?

A. WAF.

B. UPS firewall.

C. Backup firewall.

D. HSM.

Correct Answer

A


216. Question 15

Which technology can actively block detected suspicious network traffic?

A. IPS.

B. IDS only.

C. SIEM only.

D. Honeypot only.

Correct Answer

A


217. Question 16

What does application allowlisting primarily do?

A. Permit execution of approved applications.

B. Allow every application except known malware.

C. Disable all software.

D. Encrypt memory.

Correct Answer

A


218. Question 17

What does sandboxing provide?

A. Controlled environment for observing suspicious behavior.

B. Guaranteed malware removal.

C. Physical access control.

D. Data classification.

Correct Answer

A


219. Question 18

What is a honeypot?

A. Deceptive system or resource designed to attract suspicious interaction.

B. Production backup server.

C. Authentication server.

D. Encryption key store.

Correct Answer

A


220. Question 19

What is a major limitation of AI-based detection?

A. Output can be inaccurate and requires validation/context.

B. AI has no false positives.

C. AI automatically accepts organizational risk.

D. AI does not require data.

Correct Answer

A


221. Question 20

Which statement is MOST accurate?

A. Effective incident management combines preparation, detection, response, mitigation, remediation, recovery, reporting, and learning.

B. Incident response is purely technical.

C. Firewalls eliminate the need for incident response.

D. Recovery eliminates the need for lessons learned.

Correct Answer

A


Part CLXIII β€” Original CISSP-Style Practice Questions

222. Practice Question 1

Security detects suspicious outbound connections from a critical server, but the evidence is not yet sufficient to confirm compromise.

What should the incident handler do FIRST?

A. Validate and triage the activity while preserving relevant evidence.

B. Publicly announce a breach.

C. Permanently destroy the server.

D. Ignore the activity.

Correct Answer

A


223. Practice Question 2

An attacker is actively encrypting production file servers. Forensics requests that systems remain online for several hours so memory can be collected.

What should management prioritize?

A. Protect critical operations and contain harm while preserving evidence as safely and practically as possible.

B. Evidence must always take priority over ongoing damage.

C. Do nothing until all evidence is acquired.

D. Delete backups.

Correct Answer

A


224. Practice Question 3

A compromised endpoint has been isolated, but the attacker still has active cloud sessions using stolen authentication tokens.

What should happen NEXT?

A. Revoke compromised sessions/tokens and continue scope investigation.

B. Assume isolation completely contained the incident.

C. Reconnect the endpoint.

D. Disable logging.

Correct Answer

A


225. Practice Question 4

Malware has been removed from a server, but the exploited vulnerability remains unpatched.

Which stage is incomplete?

A. Remediation.

B. Detection.

C. Reporting.

D. Classification.

Correct Answer

A


226. Practice Question 5

A company restores a compromised server from yesterday's backup, but the attacker originally gained access three weeks earlier.

What is the GREATEST concern?

A. The backup may already contain attacker persistence or compromised state.

B. Newer backups are always safe.

C. Restored systems need no validation.

D. Backups eliminate incident investigation.

Correct Answer

A


227. Practice Question 6

Following a major incident, the organization documents lessons but assigns no owners or due dates to corrective actions.

What is the PRIMARY weakness?

A. Lessons learned are unlikely to produce measurable improvement.

B. Documentation is unnecessary.

C. Root-cause analysis should never create action items.

D. Recovery automatically fixes every weakness.

Correct Answer

A


228. Practice Question 7

A WAF is blocking attacks against a vulnerable customer application. Management proposes canceling the application's security fix because the WAF appears effective.

What is the BEST response?

A. Treat the WAF as a protective layer while still remediating the underlying application weakness.

B. Never patch applications behind a WAF.

C. A WAF guarantees no compromise.

D. Disable application testing.

Correct Answer

A


229. Practice Question 8

An IPS begins blocking legitimate customer transactions after a new rule is activated.

What is the BEST action?

A. Investigate and tune or rollback the problematic prevention rule while maintaining appropriate protection.

B. Ignore customer impact.

C. Disable every security control permanently.

D. Treat all blocked customers as attackers.

Correct Answer

A


230. Practice Question 9

An organization wants strict control over executables on highly sensitive administrative workstations.

Which approach BEST supports this goal?

A. Application allowlisting combined with additional endpoint controls.

B. Denylisting only.

C. No endpoint restrictions.

D. Shared administrator passwords.

Correct Answer

A


231. Practice Question 10

A honeypot begins making outbound connections to production databases after an attacker compromises it.

What should security conclude?

A. The deception environment lacks sufficient containment and must be isolated.

B. Honeypots should have unrestricted production access.

C. The behavior is normal and should be ignored.

D. Honeypots cannot be compromised.

Correct Answer

A


232. Practice Question 11

An MDR provider misses a major incident because an organization failed to send cloud identity logs to the provider.

What is the BEST conclusion?

A. Effective third-party monitoring depends on clearly defined telemetry, responsibilities, and integration.

B. The provider automatically has access to every log.

C. Outsourcing eliminates internal governance.

D. Identity logs do not matter.

Correct Answer

A


233. Practice Question 12

An AI detection system flags thousands of normal activities after a major business-process change.

What should security do?

A. Reevaluate model baselines/tuning and validate alerts against the changed environment.

B. Automatically classify all employees as malicious.

C. Remove all human review.

D. Ignore data quality.

Correct Answer

A


234. Practice Question 13

An organization has excellent firewalls and endpoint protection but has never practiced an incident-response scenario.

What is the GREATEST concern?

A. Technical controls may not compensate for untested coordination and decision-making processes.

B. Incident response is unnecessary when firewalls exist.

C. Tabletop exercises create vulnerabilities.

D. Security incidents cannot occur.

Correct Answer

A


235. Practice Question 14

An employee receives an unexpected MFA request and reports it immediately. The SOC discovers password compromise before the attacker successfully authenticates.

What principle does this BEST demonstrate?

A. Human reporting can function as an important detection control.

B. MFA fatigue cannot occur.

C. Users should never report unusual authentication.

D. Incident detection is purely automated.

Correct Answer

A


236. Practice Question 15

Security notices that the same ransomware entry method has caused three incidents in six months.

What should management prioritize?

A. Root-cause remediation rather than repeatedly performing only containment and recovery.

B. Faster rebuilding only.

C. Stop lessons-learned reviews.

D. Accept recurring compromise as normal.

Correct Answer

A


Part CLXIV β€” Incident Lifecycle Memory Table

PhasePrimary Question
PreparationAre we ready?
DetectionDid something suspicious happen?
TriageIs it real and how urgent?
ContainmentHow do we limit damage?
EradicationHow do we remove malicious presence?
RemediationHow do we correct the weakness?
RecoveryHow do we restore trusted operations?
ReportingWho must know?
Lessons LearnedHow do we prevent recurrence?

Part CLXV β€” Incident Decision Table

SituationLikely Priority
Low-confidence informational alertValidate
Confirmed malware, isolated low-value hostContain/investigate
Active privileged-account takeoverUrgent escalation
Active ransomware on critical systemsMajor incident/crisis response
Sensitive regulated-data exposureSecurity + legal/privacy escalation
Recurring incidentRoot-cause remediation

Part CLXVI β€” Detection/Prevention Memory Table

ControlMain Role
Network firewallControl network flows
NGFWApplication/threat-aware firewalling
WAFProtect web application traffic
IDSDetect/alert
IPSDetect and block
AllowlistingPermit approved items
DenylistingBlock known prohibited items
SandboxObserve suspicious code safely
HoneypotDeception/detection
HoneynetNetwork of deceptive systems
Anti-malwareDetect/prevent malicious software
EDREndpoint visibility/detection/response
AI/MLBehavioral/anomaly analysis support

Part CLXVII β€” Mitigation vs Remediation Table

MitigationRemediation
Reduce immediate riskCorrect root weakness
Often temporaryIntended as lasting corrective action
Example: isolate serviceExample: patch vulnerability
May preserve business continuityRemoves/reduces cause

Part CLXVIII β€” Response Roles Memory Table

StakeholderPrimary Concern
SecurityDetection, investigation, containment
IT OperationsSystems and restoration
LegalLegal obligations and risk
PrivacyPersonal-data impact
HRPersonnel issues
Business OwnerMission/operational impact
ExecutivesStrategic risk decisions
CommunicationsExternal/internal messaging
Third PartyContracted specialist/support role

Part CLXIX β€” Key Terms

Incident Management

Coordinated handling of security incidents from detection through response, recovery, remediation, and learning.

Security Alert

Notification indicating activity matches defined detection criteria.

Incident Triage

Validation, classification, and prioritization of potential incidents.

Incident Severity

Assessment of potential or actual incident impact.

Escalation

Transfer of incident responsibility or awareness to higher authority or specialized personnel.

Containment

Actions that limit incident spread or impact.

Isolation

Separation of compromised or suspicious assets from other systems or communications.

Mitigation

Reduction of incident risk or impact without necessarily removing the underlying cause.

Eradication

Removal of malicious presence and persistence.

Remediation

Correction of the underlying vulnerability, configuration, process, or other weakness.

Recovery

Restoration of validated trustworthy operational capability.

Lessons Learned

Post-incident review intended to identify improvements and prevent recurrence.

Playbook

Scenario-oriented incident-response guidance.

Runbook

Task-oriented operational procedure.

Tabletop Exercise

Discussion-based simulation used to test roles, plans, and decision making.

Firewall

Control that manages network traffic flows according to security policy. NIST's firewall guidance remains SP 800-41 Rev. 1.

NGFW

Next-Generation Firewall combining network control with deeper application/threat awareness.

WAF

Web Application Firewall focused on HTTP/HTTPS application traffic.

IDS

Intrusion Detection System.

IPS

Intrusion Prevention System.

Allowlisting

Permit only explicitly approved items or activity.

Denylisting

Block explicitly prohibited items while permitting others according to policy.

Sandboxing

Execution or analysis within an isolated controlled environment.

Honeypot

System or resource intentionally designed to attract potential intruders.

Honeynet

Network of systems designed for deception, monitoring, or attacker observation.

Anti-Malware

Technology used to identify, block, quarantine, or remove malicious software.

EDR

Endpoint Detection and Response.

MDR

Managed Detection and Response.

MSSP

Managed Security Service Provider.

Model Drift

Loss of model accuracy as the environment represented by training/baseline data changes.

Defense in Depth

Layering multiple complementary security controls so that failure of one does not imply complete security failure.


CISSP Exam Focus

When facing an incident-management question, use this sequence:

IS IT REALLY AN INCIDENT?
↓
WHAT IS THE IMPACT?
↓
WHO HAS AUTHORITY?
↓
WHAT MUST BE CONTAINED FIRST?
↓
WHAT EVIDENCE MUST BE PRESERVED?
↓
WHAT CAUSED THE INCIDENT?
↓
HOW DO WE REMEDIATE?
↓
HOW DO WE RESTORE TRUSTED SERVICE?
↓
WHO MUST BE NOTIFIED?
↓
WHAT MUST CHANGE AFTERWARD?

When facing a detection/prevention control question:

WHAT ARE WE PROTECTING?
↓
WHAT ATTACK PATH EXISTS?
↓
DO WE NEED PREVENTION, DETECTION, OR BOTH?
↓
WHERE SHOULD THE CONTROL OPERATE?
↓
WHAT FALSE-POSITIVE IMPACT EXISTS?
↓
HOW WILL WE MONITOR AND TUNE IT?

Remember:

  • CISSP Domain 7 currently represents 13% of the examination, and Objective 7.6 explicitly includes detection, response, mitigation, reporting, recovery, remediation, and lessons learned.

  • NIST SP 800-61 Rev. 3 became final in April 2025 and supersedes Rev. 2. It integrates incident response throughout cybersecurity risk management and CSF 2.0.

  • An event is not automatically an incident.

  • An alert is not proof of compromise.

  • Triage validates and prioritizes.

  • Incident priority should reflect business impact and context.

  • Containment limits spread.

  • Eradication removes malicious presence.

  • Mitigation reduces risk.

  • Remediation addresses the underlying weakness.

  • Recovery must restore a trustworthy state.

  • The newest backup is not necessarily the cleanest backup.

  • Evidence considerations matter during containment.

  • Human safety and critical mission protection can outweigh perfect forensic preservation.

  • Notification requirements depend on legal, regulatory, contractual, and privacy context.

  • Security analysts should not independently make legal-notification decisions.

  • Communications should be coordinated.

  • Lessons learned should create assigned corrective actions.

  • Repeated incidents suggest inadequate root-cause remediation.

  • Playbooks provide scenario guidance.

  • Runbooks provide detailed operational procedures.

  • Incident-response automation can improve speed but can magnify false-positive consequences.

  • Tabletop exercises help test decisions and coordination.

  • Current Objective 7.7 explicitly includes network/next-generation/web application firewalls, IDS/IPS, whitelisting/blacklisting, third-party services, sandboxing, honeypots/honeynets, anti-malware, and AI/ML tools.

  • Firewalls enforce traffic policy; they do not solve every security problem.

  • NIST SP 800-41 Rev. 1 remains NIST's final dedicated firewall-policy publication.

  • WAFs focus on web application traffic.

  • WAF protection does not remove the obligation to fix vulnerable applications.

  • IDS primarily detects.

  • IPS can prevent/block.

  • IPS false positives can affect availability.

  • Allowlisting supports default-deny execution models.

  • Allowlisting does not prevent malicious misuse of approved tools.

  • Denylisting depends heavily on knowledge of prohibited activity.

  • Outsourcing operational security does not outsource organizational risk accountability.

  • Sandboxing provides behavioral evidence, not absolute certainty.

  • Honeypots are intentionally attractive deception resources.

  • Deception environments should be isolated sufficiently to prevent attacker pivoting.

  • Anti-malware should be layered with other endpoint controls.

  • AI/ML-based detection tools are explicitly part of the current CISSP outline.

  • AI outputs require evidence-based validation.

  • High-impact automated response actions require safeguards and human governance.

  • Defense in depth assumes any single control may fail.


Lesson Summary

Lesson Twenty-Six connected incident management with the defensive technologies used to prevent, detect, contain, and investigate security threats.

The complete incident-management model is:

PREPARE
↓
DETECT
↓
TRIAGE
↓
CONTAIN
↓
INVESTIGATE
↓
ERADICATE
↓
REMEDIATE
↓
RECOVER
↓
REPORT
↓
LEARN

NIST's current SP 800-61 Rev. 3 treats incident response as part of the broader cybersecurity risk-management lifecycle, with Govern, Identify, Protect, Detect, Respond, and Recover all contributing to effective incident-response capability.

The SierraTec Secure INCIDENT model summarizes the response process:

I β€” Identify and Validate
N β€” Name Priority and Owner
C β€” Contain the Threat
I β€” Investigate and Preserve Evidence
D β€” Defeat the Root Cause
E β€” Establish Trusted Recovery
N β€” Notify Appropriately
T β€” Transform Lessons Into Improvement

You learned the essential differences among:

CONTAINMENT
Stop spread

MITIGATION
Reduce risk

ERADICATION
Remove malicious presence

REMEDIATION
Correct the weakness

RECOVERY
Restore trusted operation

You then examined Domain 7.7 defensive technologies.

NETWORK FIREWALL
↓
NGFW
↓
WAF
↓
IDS / IPS
↓
ALLOWLISTING
↓
ANTI-MALWARE / EDR
↓
SANDBOXING
↓
DECEPTION
↓
AI / ML ANALYTICS

The current ISC2 examination outline explicitly includes these technology categories under operational detection and preventive measures.

You learned that a firewall controls traffic according to policy but does not create complete security. NIST SP 800-41 Rev. 1 remains its final dedicated firewall policy guidance.

You also learned how deception technologies can create strong detection signals. NIST defines a honeypot as a system or resource intentionally designed to attract potential intruders.

Finally, you examined automation and AI.

TELEMETRY
↓
ANALYTICS
↓
AI / ML
↓
RISK SIGNAL
↓
HUMAN / AUTOMATED DECISION
↓
RESPONSE

AI improves scale and correlation but does not replace:

  • evidence;

  • accountability;

  • human judgment;

  • risk ownership.

The central Lesson Twenty-Six principle is:

Incident management is not merely a technical cleanup activity. Effective response requires prepared authority, accurate detection, risk-based prioritization, rapid containment, evidence-aware investigation, root-cause remediation, validated recovery, coordinated communications, and continuous improvementβ€”supported by layered preventive and detective controls that are themselves monitored, tested, and tuned.


Exam Readiness Check

Before continuing to Lesson Twenty-Seven, make sure you can explain without reviewing:

  • What incident management means.

  • The current CISSP 7.6 incident-management elements.

  • How NIST SP 800-61 Rev. 3 changed the framing of incident response.

  • Event versus alert versus incident versus crisis.

  • Why incident preparation matters.

  • What a CSIRT/CIRT is.

  • Why security, IT, legal, privacy, HR, communications, and management may all participate.

  • Why incident-response authority should be established in advance.

  • What incident detection means.

  • What triage means.

  • How incident classification works.

  • Severity versus priority.

  • What escalation means.

  • What containment does.

  • Short-term versus longer-term containment.

  • Why isolation may preserve investigation capability.

  • Why human safety and mission impact matter during containment.

  • What mitigation means.

  • What eradication means.

  • What remediation means.

  • Mitigation versus remediation.

  • What recovery means.

  • Why recovery requires validation.

  • Why the latest backup may still be compromised.

  • Why heightened monitoring should follow recovery.

  • Why incident reporting requires coordination.

  • Why legal/privacy personnel may determine external notification requirements.

  • Why technical personnel should not independently communicate with media.

  • Why incident documentation matters.

  • How evidence preservation interacts with response urgency.

  • What lessons learned means.

  • Why lessons learned should result in assigned corrective actions.

  • What root-cause analysis means.

  • What a playbook is.

  • What a runbook is.

  • Playbook versus runbook.

  • How automation helps incident response.

  • Why automation can create business disruption.

  • What tabletop exercises test.

  • MTTD concept.

  • Why MTTR must be explicitly defined.

  • Preventive versus detective versus corrective controls.

  • What a network firewall does.

  • What an NGFW adds conceptually.

  • What a WAF protects.

  • Network firewall versus WAF.

  • IDS versus IPS.

  • Why IPS false positives can affect availability.

  • What allowlisting means.

  • What denylisting means.

  • Allowlisting versus denylisting.

  • Why trusted applications can still be abused.

  • What third-party security services are.

  • MSSP versus MDR conceptually.

  • Why outsourcing does not transfer risk ownership.

  • What sandboxing does.

  • Why malware may evade sandboxes.

  • What a honeypot is.

  • What a honeynet is.

  • Why deception systems need containment.

  • Why honeypot interaction can provide a high-value detection signal.

  • What anti-malware does.

  • Signature versus behavior-based malware detection.

  • What EDR provides conceptually.

  • Why EDR is broader than traditional antivirus.

  • How endpoint isolation can support containment.

  • How AI and ML may support security operations.

  • Why AI can generate false positives and incorrect conclusions.

  • What model drift means.

  • Why AI-generated incident summaries must be validated.

  • Why high-impact response decisions require governance.

  • What defense in depth means operationally.

  • Why detection without response is insufficient.

  • Why prevention without monitoring is insufficient.


Coming Next

Lesson Twenty-Seven: Backup, Recovery Strategies, Disaster Recovery, and Business Continuity Operations

Lesson Twenty-Seven will continue CISSP Domain 7 and concentrate primarily on Objectives 7.10 through 7.13:

7.10 β€” Implement Recovery Strategies

Including:

  • backup storage strategies;

  • cloud storage;

  • onsite and offsite storage;

  • recovery-site strategies;

  • cold sites;

  • hot sites;

  • resource-capacity agreements;

  • multiple processing sites;

  • system resilience;

  • high availability;

  • Quality of Service;

  • fault tolerance.

7.11 β€” Implement Disaster Recovery Processes

Including:

  • response;

  • personnel;

  • communications;

  • assessment;

  • restoration;

  • training and awareness;

  • lessons learned.

7.12 β€” Test Disaster Recovery Plans

Including:

  • read-through/tabletop;

  • walkthrough;

  • simulation;

  • parallel testing;

  • full interruption;

  • stakeholder and regulator communications.

7.13 β€” Participate in Business Continuity Planning and Exercises.

Lesson Twenty-Seven will cover:

  • backup architecture;

  • full backups;

  • incremental backups;

  • differential backups;

  • snapshots;

  • replication;

  • immutable backups;

  • offline backups;

  • the 3-2-1 concept;

  • backup encryption;

  • backup integrity;

  • restoration testing;

  • RTO;

  • RPO;

  • MTD/MAD concepts;

  • recovery tiers;

  • cold sites;

  • warm sites;

  • hot sites;

  • reciprocal arrangements;

  • cloud recovery;

  • geographic diversity;

  • high availability;

  • fault tolerance;

  • clustering;

  • redundancy;

  • failover;

  • QoS;

  • Disaster Recovery Plan activation;

  • emergency communications;

  • damage assessment;

  • restoration priorities;

  • failback;

  • tabletop exercises;

  • walkthroughs;

  • simulations;

  • parallel tests;

  • full-interruption tests;

  • BC versus DR;

  • business-process continuity;

  • manual workarounds;

  • critical dependencies;

  • supplier continuity;

  • original SierraTec models;

  • CISSP exam traps;

  • knowledge checks;

  • scenario questions.

The central Lesson Twenty-Seven question will be:

How should an organization design, implement, test, and continuously improve backup, recovery, disaster-recovery, and business-continuity capabilities so critical operations can survive disruption and return to a trusted state within defined business requirements?


Publication and Independence Notice

This lesson is independently developed educational material for the SierraTec Secure CISSP Certification Preparation Course.

CISSP is administered by ISC2. SierraTec Secure's program is independent certification-preparation material and should not be represented as official ISC2 training unless separately authorized.

The current Domain 7.6 and 7.7 content was verified against the official ISC2 CISSP Certification Exam Outline. Objective 7.6 currently lists detection, response, mitigation, reporting, recovery, remediation, and lessons learned; Objective 7.7 currently lists firewalls, IDS/IPS, whitelisting/blacklisting, third-party security services, sandboxing, honeypots/honeynets, anti-malware, and machine-learning/AI-based tools.

Incident-response material was updated to NIST SP 800-61 Rev. 3, finalized April 3, 2025 and superseding Rev. 2. NIST's current model integrates incident response across cybersecurity risk management and the NIST CSF 2.0 functions.

Firewall concepts were supplemented with NIST SP 800-41 Rev. 1, which remains NIST's final dedicated publication on firewall technologies and firewall policy.

The SierraTec Secure INCIDENT and SHIELD frameworks, diagrams, scenarios, comparisons, knowledge checks, and practice questions are original educational content and are not actual, recalled, leaked, or official CISSP examination questions.

Sallieu Kanu

Sallieu Kanu

Product Designer
0
Best Seller
Faithful User
Expert Vendor
King Seller

Class Sessions

1- Introduction to CISSP 2- Thinking Like a CISSP: Security Principles, Risk, and Professional Decision-Making 3- Lesson 1 4- Lesson 3 5- Lesson 4: Risk Management, Risk Assessment, and Risk Treatment 6- Lesson 5: Threat Modeling, Supply-Chain Risk, and Third-Party Risk 7- Lesson 6: Legal, Regulatory, Privacy, Compliance, and Investigation Foundations 8- Lesson 7: Asset Security and Information Lifecycle Management 9- Lesson 8: Security Architecture Foundations and Protection Mechanisms 10- Lesson 9: Security Models, Trusted Systems, and Secure Design 11- Lesson 10: Cryptography and Cryptographic Solutions 12- Lesson 11: Cryptographic Attacks and Public Key Infrastructure 13- Lesson 12: Physical and Facility Security Architecture 14- Lesson 13: Information System Lifecycle and Secure Engineering 15- Lesson 14: Communication and Network Security Foundations 16- Lesson 15: Secure Network Components and Infrastructure Protection 17- Lesson 16: Secure Communication Channels, Remote Access, and Third-Party Connectivity 18- Lesson 17: Identity and Access Management Foundations 19- Lesson 18: Authentication Systems, Federation, SSO, and Identity Protocols 20- Lesson 19: Authorization Models and Access-Control Enforcement 21- Lesson 20: Identity Provisioning, Access Reviews, Privileged Access, and Account Lifecycle 22- Lesson 21: Security Assessment and Testing Foundations 23- Lesson 22: Advanced Security Control Testing and Vulnerability Management 24- Lesson 23: Security Metrics, Test Analysis, Reporting, and Audit Assurance 25- Lesson 24: Security Operations, Investigations, Evidence, and Logging Foundations 26- Lesson 25: Configuration Management, Resource Protection, Patch Management, and Change Control 27- Lesson 26: Incident Management and Operational Detection and Prevention 28- Lesson 27: Backup, Recovery Strategies, Disaster Recovery, and Business Continuity Operations

Join Us Today

We'll send the best deals and offers to your email. No spam, ever.

GDPR

When you visit any of our websites, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and manage your preferences. Please note, that blocking some types of cookies may impact your experience of the site and the services we are able to offer.