* According to NIST SP800-61, the incident response lifecycle consists of four phases: Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity. * When a SOC team member checks the Cisco Firepower Manager dashboard for further isolation actions, they are working within the Eradication and Recovery phase. * This phase focuses on removing the threat from the environment and recovering affected systems to normal operations. References * NIST SP800-61 Computer Security Incident Handling Guide * Incident Response Phases Explained * Role of SOC in Incident Response