← Back to course

Detection and Network Incident Response

You’ll be able to

Detection and Network Incident Response

Detection combines preventive controls with logs, alerts, and context. Incident response follows preparation, detection and analysis, containment, eradication, recovery, and lessons learned. Network evidence helps determine entry path, affected assets, lateral movement, and data transfer.

Decision lens

Strong technical decisions connect evidence → mechanism → impact → response. Identify what the evidence shows, explain the system behavior that produced it, state the likely effect on people or data, and choose a response that addresses the cause without creating unnecessary disruption.

Worked example

A server begins scanning internal subnets minutes after a successful login from an unfamiliar country.

  1. 1.Correlate identity, server, firewall, and endpoint records.
  2. 2.The login and scanning sequence suggests possible account compromise and discovery.
  3. 3.Contain the account and server while preserving evidence.
  4. 4.Reset credentials, remove persistence, close the entry path, recover, and monitor.
Answer: The correlated timeline supports rapid containment while a broader scope investigation continues.
Checkpoint

Which activity belongs in lessons learned?

Checkpoint

Which response best demonstrates complete reasoning about network security evidence and response?

On the exam

For a scenario about network security evidence and response, identify the decisive evidence before naming a response. A defensible conclusion here is: The correlated timeline supports rapid containment while a broader scope investigation continues.

Answer the 2 checkpoints as you read.

Sign in to save your progress