To access material, start machines and answer questions login.
The attacker is inside the Nexus Financial environment. The Detection and Analysis phase confirmed the compromise, identified the affected accounts, and mapped the initial attack chain. This room covers Response and Recovery, the phase where the team transitions from understanding the incident to actively resolving it. In SP 800-61r2 terms, this maps to the Containment, Eradication, and Recovery phase.
Learning Objectives
- Understand Response and Recovery and its place in the SP 800-61r2 framework
- Learn the difference between containment strategies and when to apply each
- Understand how ATT&CK maps to attacker behavior and informs containment decisions
- Understand what eradication and recovery involve in the current Microsoft 365 incident
- Use to analyze attacker post-compromise activity and identify what needs to be contained and eradicated
Prerequisites
Although this room can be completed as a standalone, it is highly recommended to complete the following rooms before starting this one:
Familiarity with queries is required for the practical tasks. It is also recommended to complete the Microsoft 365 for the module before starting this room.
Module Chain
This module follows a single security incident at Nexus Financial from start to finish across four rooms:
| Room | What You Do |
|---|---|
| 1 - Preparation | Review Nexus Financial's security posture before the attack |
| 2 - Detection and Analysis | Detect the incident and analyze it in |
| 3 - Response and Recovery | Make containment decisions, confirm the attacker is gone, and identify root causes |
| 4 - Post-Incident Activity | Reconstruct the timeline of the attack and revisit what went wrong |
Note: This is Room 3 of 4 in the Incident Response module. All four rooms follow the same incident at Nexus Financial.
I am ready to start!
Ready to learn Cyber Security?
The Response and Recovery room is only available for premium users. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in