Course 6: Sound the Alarm Detection and Response Flashcards

1
Q

The first phase of the NIST Incident Response Lifecycle is Preparation. What are the other phases?

A
  1. Containment , Eradication and Recovery
  2. Detection and Analysis
  3. Post-Incident Activity
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What type of process is the NIST Incident Response Lifecycle?

A

The NIST Incident Response Lifecycle is a cyclical process. This means that phases in the lifecycle can be revisited or repeated as incident investigations progress.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Fill in the blank: An _____ is an observable occurrence on a network, system, or device.

A

Event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A security professional investigates an incident. Their goal is to gain information about the 5 W’s, which include what happened and why. What are the other W’s?

A
  1. Where the incident took place
  2. Who triggered the incident
  3. When the incident took place
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly