Chapter 22: Security Incidents Flashcards

1
Q

MOM

A

motive, opportunity, means

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

evidence preservation

A

maintain chain of custody and cryptographic hashes of all digital evidence and controlling access to the evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

four phases of evidence handling

A

identification, collection, acquisition, and preservation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

runbook

A

collection of procedures which the IR team follows for specific types of incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

incident classification criteria

A

prioritize IR assets and consider the impact and type of incident, urgency with which the response must be started

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

seven phases of incident management

A

detection, response, mitigation, reporting, recovery, remediation, and lessons learned

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

containment during the response phase

A

to prevent or reduce any further damage from the incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

remediation phase of incident management

A

security controls are deployed or changed to prevent the incident from recurring; changes to firewall or IDS/IPS rules, identification of IOAs and IOCs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

IOA

A

indicators of attack; to detect an attack in real time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

IOC

A

indicator of compromise, which tell when an attack has been successful and security has been compromised

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

characteristic of admissible evidence

A

relevant to the case, reliable (must be consistent with fact and must not be based on opinion or be circumstantial), and legally obtained

How well did you know this?
1
Not at all
2
3
4
5
Perfectly