Stage 1 — IR Lifecycle Order
NIST SP 800-61 defines six phases that all computer security incident handling must follow. The phases below have been scrambled. Drag them into the correct order from top (Phase 1) to bottom (Phase 6).
NIST SP 800-61r2 Section 3.1 lists these six phases. "Detection & Analysis" is sometimes called "Identification" in older frameworks but the 800-61 name is the exam-tested term.
Stage 2 — Decision Points
You are working the live Veridian incident. At each critical juncture you must choose the correct response action. Order of operations matters: a correct action taken in the wrong sequence (e.g., eradicating before containing) is still wrong.
Each decision is keyed to one IR or forensic principle (order of volatility, CONTAIN-before-ERADICATE, chain of custody, no ransom, image-before-wipe). Getting the principle right is what matters.
Stage 3 — Forensic Timeline Reconstruction
Forensic investigation of the Veridian breach surfaced six artifacts each with an exact timestamp. Reconstruct the attack chronology by dragging the artifacts into the correct time order (earliest first). Order of volatility and chain-of-custody notes are embedded in each card.
A forensic timeline correlates artifacts across disk images, memory dumps, SIEM logs, and network captures. All sources must be time-synced (NTP) and their hashes verified before the timeline is admissible.
Incident Closed — IR Analyst Certified
You sequenced the NIST 800-61 lifecycle correctly, applied the right response actions in the right order under pressure, and reconstructed the forensic timeline of the Veridian ransomware breach. Chain of custody maintained throughout.