4.2 Policies / Processes Incident Response Flashcards

1
Q

During which incident response phase is the preservation of evidence performed?

A

Containment, eradication, and recovery: preserve forensic and incident information for future needs, prevent future attacks or bring up an attacker on criminal charges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Incident Response Phase - PREPARATION

A

incident response team conducts training, prepares their incident response kits, and researches threats and intelligence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Incident Response Phase - DETECTION and ANALYSIS

A

an organization focuses on monitoring and detecting any possible malicious events or attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Incident Response Phase - POST INCIDENT ACTIVITY

A

the organization conducts after-action reports, creates lessons learned, and conducts follow-up actions to better prevent another incident from occurring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Lessons Learned Report

A

provides you with the details of the incident, its severity, the remediation method, and, most importantly, how effective your response was. Additionally, it provides recommendations for improvements in the future

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does a forensic analysis report not provide?

A

recommendations for future improvements, even though it provides many of the other details

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Trend Analysis Report

A

describes whether behaviors have increased, decreased, or stayed the same over time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

chain of custody report

A

chronological documentation or paper trail that records the custody, control, transfer, analysis, and disposition of physical or electronic evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly