During the detection and analysis phase of the NIST incident response process life cycle, which sign category is used to describe that an incident might occur in the future?

IT Exam Items Repository › Category: CCNA CyberOps › During the detection and analysis phase of the NIST incident response process life cycle, which sign category is used to describe that an incident might occur in the future?

During the detection and analysis phase of the NIST incident response process life cycle, which sign category is used to describe that an incident might occur in the future?

  • attrition
  • impersonation
  • precursor
  • indicator

Explanation: There are two categories for the signs of an incident:

  • Precursor – a sign that an incident might occur in the future
  • Indicator – a sign that an incident might already have occurred or is currently occurring

Related exam: CCNA SECOPS 210-255 Dumps – Certification Practice Exam Answers
Related exam: CyberOps Associate (Version 1.0) - CyberOps Associate (200-201) Certification Practice Exam