Course 6: Sound the Alarm Detection and Response Flashcards
1
Q
The first phase of the NIST Incident Response Lifecycle is Preparation. What are the other phases?
A
- Containment , Eradication and Recovery
- Detection and Analysis
- Post-Incident Activity
2
Q
What type of process is the NIST Incident Response Lifecycle?
A
The NIST Incident Response Lifecycle is a cyclical process. This means that phases in the lifecycle can be revisited or repeated as incident investigations progress.
3
Q
Fill in the blank: An _____ is an observable occurrence on a network, system, or device.
A
Event
4
Q
A security professional investigates an incident. Their goal is to gain information about the 5 W’s, which include what happened and why. What are the other W’s?
A
- Where the incident took place
- Who triggered the incident
- When the incident took place
5
Q
A