🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)82 / 145
Question 82 of 145
A SOC analyst receives an automated alert from the SIEM indicating unusual authentication activity. The analyst reviews correlated logs, confirms the activity is malicious rather than a false positive, documents the affected systems, and assigns a severity rating before notifying the incident response lead. According to the NIST SP 800-61 incident response lifecycle, which phase do these analyst actions primarily belong to?
Reviewed for accuracy · Report an issueNext question