Master the fundamental phases of Incident Handling and Response (IH&R). In this simulation, you will step into the shoes of a Tier 3 analyst bringing order to a chaotic, out-of-sequence incident response initiated by a junior team member.
You are the Lead Incident Responder on shift. A high-severity alert fired indicating ransomware behavior on a critical database server. A junior analyst reacted immediately to the alert, but their response was scattered, poorly documented, and severely out of order—risking the destruction of forensic evidence and business continuity.
You must step in, halt their actions, and enforce the strict incident handling framework required by industry standards (NIST/EC-Council).
SOC Collaboration Chat (MS Teams Excerpt):
The junior analyst is reacting to a critical alert entirely out of phase. By attempting eradication (wiping the drive) before containment (network isolation) and triage (understanding the scope), they destroyed forensic evidence. Moreover, they failed to ensure preparation (playbooks) and incident recording (ticketing) were handled prior to taking destructive actions.
B. Preparation -> Incident Recording -> Incident Triage -> Containment -> Eradication -> Recovery -> Post-Incident Activities
This is the definitive EC-Council / standard industry IH&R flow. Preparation establishes policies and tools. When an event fires, it is Recorded (ticketed/logged) so the SOC has a chain of custody. It is then Triaged to determine severity and true positive status. Only then do you move to Containment (stopping the bleeding), followed by Eradication (removing the threat), and finally Recovery and Post-Incident review.
A, C, & D: All these options place "Preparation" somewhere in the middle of an active incident. Preparation is a continuous phase that must occur before an attack. Additionally, these options frequently place Eradication before Containment. You cannot effectively eradicate an adversary if you haven't closed their backdoor accesses (Containment) first—they will just reinfect the host.
SOC analysts frequently confuse the middle stages of the IH&R process. Keep these strict definitions in mind: