DFIR_Introduction_Flashcards

1
Q

What is digital forensics in DFIR?

A

Digital forensics is the method of identifying, preserving, analyzing, and presenting digital evidence to aid investigations or legal proceedings.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the main activities involved in digital forensics?

A

The activities include structured techniques to recover and secure digital data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define Incident Response (IR) in DFIR.

A

Incident Response (IR) is the process of detecting, containing, and mitigating cybersecurity incidents to minimize damage and restore systems to normal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are cyber incidents?

A

Cyber incidents include unauthorized access, data theft, sabotage, and accidental threats, which can come from both insiders and outsiders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why is incident categorization important in DFIR?

A

Incident categorization (high, medium, low impact) helps prioritize responses based on urgency and severity, with high-impact incidents needing immediate action.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the preparation stage in Incident Response?

A

Preparation involves planning by establishing policies, educating staff, and setting up response tools to ensure readiness for incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What happens during the identification stage in Incident Response?

A

This stage involves detecting potential incidents using tools like SIEM systems to monitor for unusual network activity or indicators of compromise (IoCs).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the goal of containment in Incident Response?

A

Containment aims to control an incident and prevent its spread, including short-term isolation or long-term solutions like network segmentation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is eradication in Incident Response?

A

Eradication focuses on removing malware or malicious activity, such as wiping infected systems and applying security patches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What happens during the recovery phase in Incident Response?

A

Recovery restores systems to normal operation, verifies system and data integrity, and reintegrates any compromised accounts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the purpose of the post-incident review in Incident Response?

A

The post-incident review assesses the incident response process, documents lessons learned, and refines future strategies to improve security posture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the primary goal of business continuity in Incident Response?

A

Business continuity aims to minimize operational disruption during and after an incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why is data protection important in Incident Response?

A

Data protection focuses on safeguarding critical data, intellectual property, and infrastructure from potential damage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How does Incident Response help with cost reduction?

A

By quickly mitigating incidents, IR prevents the escalation of damages and financial losses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Why is reputation management important in Incident Response?

A

Effective IR helps maintain customer trust and organizational reputation by handling incidents transparently.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What role does compliance play in Incident Response?

A

Compliance ensures adherence to legal and regulatory requirements during the response, avoiding penalties.

17
Q

What is the role of evidence collection in Digital Forensics?

A

Evidence collection in forensics involves preserving data from affected systems to understand the incident’s origin and scope.

18
Q

How does digital forensics support legal investigations?

A

Digital forensics provides insights into the incident’s cause, supporting legal or regulatory investigations if required.