CYSA 7 Exam Questions and Answers with
Verified Solutions | Latest Updated 2026
Incident Act of violating an explicit security policy
NIST (National Institute of Helps organizations establish incident
Standards response
and Technology) NIST SP 800-61 capabilities, select staff, and manage
security
incidents efficiently
((Preparation, Detection & Analysis,
Containment
Eradication & Recovery, Post Incident
Activity))
Incident Response Procedures Procedures and guidelines covering
appropriate
priorities, actions, and responsibilities in
the event
of security incidents
Preparation Makes the system resilient to attacks by
hardening
systems, writing policies and procedures
((Testing
& exercises, preparing kits, Training staff))
Detection and Analysis Determine if an incident has taken place,
triage it,
and notify relevant stakeholders
, Containment Limits the scope & magnitude of the
incident by
securing data & limit impact to business
operations
& your customers
Eradication and Recovery Remove the cause of the incident and
bring the
system back to a secure state
Post-Incident Activity Analyzes the incident and responses to
identify
whether procedures or systems could be
improved.
IR Team Key people to respond to any incident that
meets
the severity & priority thresholds set out by
the IR
Plan
CSIRT (Computer Security Serves as a single point of contact for
Incident security
Response Team) incidents, typically within the SOC or an
independent team.
Incident Form Records the detail about the reporting of
an
incident and assigns it a case or job
number
Verified Solutions | Latest Updated 2026
Incident Act of violating an explicit security policy
NIST (National Institute of Helps organizations establish incident
Standards response
and Technology) NIST SP 800-61 capabilities, select staff, and manage
security
incidents efficiently
((Preparation, Detection & Analysis,
Containment
Eradication & Recovery, Post Incident
Activity))
Incident Response Procedures Procedures and guidelines covering
appropriate
priorities, actions, and responsibilities in
the event
of security incidents
Preparation Makes the system resilient to attacks by
hardening
systems, writing policies and procedures
((Testing
& exercises, preparing kits, Training staff))
Detection and Analysis Determine if an incident has taken place,
triage it,
and notify relevant stakeholders
, Containment Limits the scope & magnitude of the
incident by
securing data & limit impact to business
operations
& your customers
Eradication and Recovery Remove the cause of the incident and
bring the
system back to a secure state
Post-Incident Activity Analyzes the incident and responses to
identify
whether procedures or systems could be
improved.
IR Team Key people to respond to any incident that
meets
the severity & priority thresholds set out by
the IR
Plan
CSIRT (Computer Security Serves as a single point of contact for
Incident security
Response Team) incidents, typically within the SOC or an
independent team.
Incident Form Records the detail about the reporting of
an
incident and assigns it a case or job
number