Chapter 13 - Incident Preparation and Investigation Flashcards

1
Q

What is preserving evidence?

A

Making sure that important proof is not corrupted or even destroyed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is securing the scene?

A

This is the first job, involves documenting the physical surroundings, identifying and tagging all calves connected to the device, and taking custody of the device along with any peripherals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the incident response plan?

A

Document that lists steps to be taken when an incident occurs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is order of viotility?

A

Must be followed to preserve the most fragile data first:
(1) registers and CPU cache
(2) routing tables, ARP cache, process table, kernel statistics, RAM
(3) temporary file systems
(4) hard drive
(5) remote logging and monitoring data
(6) physical configuration and network topology
(7) archival media.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is RPO?

A

Recovery Point Objective - The maximum length of time that an organization can tolerate between backups.
RPO = “How much time’s worth of data can I lose?”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is RTO?

A

Recovery Time Objective - The length of time it will take to recover data that has been backed up.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Hot site?

A

A duplicate of the production site that has all the equipment needed for an organization to continue running, including office space and furniture, telephone jacks, computer equipment, and a live telecommunications link.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Cold site?

A

A remote site that provides office space; the customer must provide and install all the equipment needed to continue operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a Warm site?

A

A remote site that contains computer equipment but does not have active Internet or telecommunication facilities and does not have backups of data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is SIEM?

A

Security Information and Event Management - consolidate real-time security monitoring and management of security information with analysis and reporting of security events; this information includes alerts, trends, sensitivity, and correlation data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Eradication?

A

An incident response process step of finding the cause of the incident and temporarily removing any systems that may be causing damage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Containment?

A

An incident response process step of limiting the damage of the incident and isolating those systems that are impacted to prevent further damage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the Cyber Kill Chain?

A

Outlines the steps of an attack
(1) Reconnaissance
(2) Weaponization
(3) Delivery
(4) Exploitation
(5) Installation
(6) Command & Control
(7) Actions on objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is BIA?

A

Business Impact Analysis - A process that identifies the business functions and quantifies the impact a loss of these functions may have on business operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is BCP?

A

Business Continuity Plan - If important buisness activities that could result in a significant loss are interupted this document provides alternative modes of operation for business activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is DRP?

A

Disaster Recover Plan - written document that details the process for restoring IT resources

17
Q

What is Parallel Processing?

A

An incident response testing exercise that conducts the same tests simultaneously in multiple environments.

18
Q

What is a Failover Simulation?

A

An incident response testing exercise that is testing the process of temporarily switching to backup procedures after an attack.