Annex H20 Incident Response, Reporting, and Auditing Flashcards

0
Q

Incident

A

An adverse event in an information system and/or network or the threat of the occurrence of such an event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

Definition of Event as it relates to incident response

A

An event is any observable occurrence in a system and/or network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Eight (8) categories of an incident

A
Malicious code
Unauthorized access 
Inappropriate usage
Service disruption
Espionage 
Hoaxes
Spillages
Multiple Category
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Six (6) components of an Incident Response Policy

A
Preparation 
Detection
Containment
Eradication
Recovery
Follow Up
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Audit

A

An independent review and examination of records and activities to assess the adequacy of system controls, to ensure compliance with established policies and operational procedures and to recommend necessary changes in controls, policies, and procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How to conduct evidence processing

A
Immediate Action- When in doubt contact MCNOSC
	Turn off/leave system alone
	Seizure of equipment
	Technical evidence gathering
Policy or legal
Notification
Documentation
	time
	date
	individual involved with action
	description of action
chain of custody
How well did you know this?
1
Not at all
2
3
4
5
Perfectly