Ch10 Dealing with Incidents Flashcards

1
Q

the 7 steps of the Incident Response Process are: Preparation, ___, ___, Containment, ___, ___, Documentation

A

Reporting; Identification; Eradication; Recovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

the group of people whose job it is to respond to a cyber security incident is the ___

A

Cyber Incident Response Team (CIRT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

the plan for who to report an incident to depending on its severity is the ___

A

chain of escalation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

the chain of custody process includes: ___, collection method, date/time collected, person collecting it, ___, and all locations of the evidence

A

defining the data; function/qualification of the person collecting the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

when retrieving system data as evidence, always use ___ software to demonstrate that you have not altered it

A

write block enabled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

as you collect evidence, remember to ___ so you can be paid from the right people

A

track your hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

a __ recovery site might take a few days to bring online, it might have the equipment your need, but not the data

A

warm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

the first item in the order of restoration after an incident is to verify ___

A

power is working on all outlets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

a ___ is practicing the actual activities required to recover from an incident

A

failover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

the Last Modified date/time of a file is known as its ___ for backup purposes

A

archive attribute

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

a ___ is a backup of all changes since the last Full backup

A

differential backup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

an ___ is a backup of all changes since the last backup of any kind

A

Incremental

How well did you know this?
1
Not at all
2
3
4
5
Perfectly