5B Flashcards
The primary goal of the __ ___ is to activate the CIRT and contain the incident.
First responder
There are six steps taken in response to cyber incidents according to Air Force instruction _____, Cyber Incident Handling. Keep in mind that steps and terminology for the industry at large are slightly different than for the USAF.
AFI 17-203
The six steps taken in response to cyber incidents are:
- Detection and Reporting of Events
- Preliminary Analysis and Identification
- Preliminary Response Actions
- Incident Analysis
- Response and Recovery
- Post-Incident Analysis
The following describes which step in responding to a cyber incident?
- Intrusion Detection Systems (IDS) or personnel reports.
- Gather/report preliminary information.
- Begin coordinating reporting/response.
Detection and Reporting of Events
The following describes which step in responding to a cyber incident?
- Categorize the activity (if upon initial analysis you cannot
determine the cause, use Category 8: Investigating, and update as required). - Gather additional info as required.
- Classify as required.
- Send notification messages per SOP’s
Preliminary Analysis and Identification
The following describes which step in responding to a cyber incident?
- Contain incident/threat.
- Preserve data to allow for further incident analysis.
- Begin chain of custody docs.
Preliminary Response Actions
The following describes which step in responding to a cyber incident?
- is the series of analytical steps taken to find out what occurred in an incident.
- Analyze data to understand technical details, root cause(s),
and potential impact
Incident Analysis
The following describes which step in responding to a cyber incident?
- Prevent further damage.
- Restore integrity of systems.
- Implement follow-up strategies
Response and Recovery
The following describes which step in responding to a cyber incident?
- Review lessons learned.
- Root cause(s).
- Problems executing COAs.
- Missing policies/procedures.
- Inadequate infrastructure.
Post-Incident Analysis