4.2 Policies / Processes Incident Response Flashcards
During which incident response phase is the preservation of evidence performed?
Containment, eradication, and recovery: preserve forensic and incident information for future needs, prevent future attacks or bring up an attacker on criminal charges
Incident Response Phase - PREPARATION
incident response team conducts training, prepares their incident response kits, and researches threats and intelligence
Incident Response Phase - DETECTION and ANALYSIS
an organization focuses on monitoring and detecting any possible malicious events or attacks
Incident Response Phase - POST INCIDENT ACTIVITY
the organization conducts after-action reports, creates lessons learned, and conducts follow-up actions to better prevent another incident from occurring
Lessons Learned Report
provides you with the details of the incident, its severity, the remediation method, and, most importantly, how effective your response was. Additionally, it provides recommendations for improvements in the future
What does a forensic analysis report not provide?
recommendations for future improvements, even though it provides many of the other details
Trend Analysis Report
describes whether behaviors have increased, decreased, or stayed the same over time
chain of custody report
chronological documentation or paper trail that records the custody, control, transfer, analysis, and disposition of physical or electronic evidence