Which of the following steps in the incident response process involves developing a hypothesis of possible attack paths and using various sources to confirm or deny the hypothesis?
Investigation is the incident response step that involves analyzing evidence, developing hypotheses, and confirming or denying possible attack paths. During investigation, analysts review logs, endpoint data, network telemetry, alerts, threat intelligence, and user activity to determine what happened, how the attacker operated, and what systems were affected. Identification is the stage where an event is recognized as a potential incident. Preparation involves policies, tools, training, playbooks, and readiness before an incident occurs. Containment focuses on limiting the attacker’s access and preventing further damage after the incident is understood enough to act. Because the question specifically mentions forming and testing hypotheses using multiple sources, the activity is investigative analysis, making investigation the correct answer.
================
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit