IR Command

Veridian Regional Hospital — live ransomware/intrusion incident

NIST SP 800-61 · SY0-701 4.8 / 4.9
Stages0 / 3
Security+ Hub
Active Incident — Veridian Regional Hospital At 09:02 a staff nurse clicked a phishing link. By 10:14 ransomware has begun encrypting the EHR file server. You are the IR lead. Three tasks must be completed before you can close the incident and issue your certification.

Stage 1 — IR Lifecycle Order

NIST SP 800-61 defines six phases that all computer security incident handling must follow. The phases below have been scrambled. Drag them into the correct order from top (Phase 1) to bottom (Phase 6).

Objective: arrange all six NIST 800-61 phases in the correct sequence. Every position must be right; a single transposition fails the check.
Drag phases into the correct order (Phase 1 at top, Phase 6 at bottom)

NIST SP 800-61r2 Section 3.1 lists these six phases. "Detection & Analysis" is sometimes called "Identification" in older frameworks but the 800-61 name is the exam-tested term.

Stage 2 — Decision Points

You are working the live Veridian incident. At each critical juncture you must choose the correct response action. Order of operations matters: a correct action taken in the wrong sequence (e.g., eradicating before containing) is still wrong.

Objective: select the right action for all five decision points. Every choice is graded against the IR key; one wrong answer blocks completion.

Each decision is keyed to one IR or forensic principle (order of volatility, CONTAIN-before-ERADICATE, chain of custody, no ransom, image-before-wipe). Getting the principle right is what matters.

Stage 3 — Forensic Timeline Reconstruction

Forensic investigation of the Veridian breach surfaced six artifacts each with an exact timestamp. Reconstruct the attack chronology by dragging the artifacts into the correct time order (earliest first). Order of volatility and chain-of-custody notes are embedded in each card.

Objective: arrange all six evidence artifacts into chronological order. Every position must be correct; a swap fails the check.
Drag artifacts into chronological order — earliest event at top

A forensic timeline correlates artifacts across disk images, memory dumps, SIEM logs, and network captures. All sources must be time-synced (NTP) and their hashes verified before the timeline is admissible.

Incident Closed — IR Analyst Certified

You sequenced the NIST 800-61 lifecycle correctly, applied the right response actions in the right order under pressure, and reconstructed the forensic timeline of the Veridian ransomware breach. Chain of custody maintained throughout.

NIST SP 800-61 Lifecycle Order of Volatility · RFC 3227 Chain of Custody SY0-701 4.8 — Incident Response SY0-701 4.9 — Digital Forensics