What should you create to prevent spoofing of the internal network?
Which step should be performed immediately after identifying a critical vulnerability affecting internet-facing systems?
Which protocol is responsible for resolving IP addresses to domain names?
Move each NIST Incident Response Lifecycle phase from the list on the left to the correct description on the right.
Note: You will receive partial credit for each correct answer.

During which stage of the incident response lifecycle are security incidents identified and prioritized?