Domain 4 - Incident Response and Recovery Flashcards

1
Q

IP Plan Elements

A
  1. Statement of Purpose
  2. Strategies and goals for incident response.
  3. Approach to incident response.
  4. Communication with other groups.
  5. Senior leadership approval.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NIST SP 800-61

A

Incident Response Plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Communication Plans

A

Ensure that all participants have timely, accurate information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is crucial for effective incident identification?

A

Monitoring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

SIEM

A

SECURITY INCIDENT AND EVENT MANAGEMENT

Security solution that collects information from diverse sources, analyzes it for signs of security incidents, and retains it for later use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

First responder responsibilities

A

Isolate affected systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Highest priority of a first responder must do what?

A

Containing damage through isolation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Second Step for First Responder?

A

Escalate and Notify

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Containment Strategy Evalutation

A
  1. Damage Potential
  2. Evidence Preservation
  3. Service availability
  4. Resource requirements.
  5. Expected effectiveness.
  6. Solution Time frame
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Evidence types

A

Real - Tangible Objects
Documentary - Written/Digital Information
Testimonial - Witness Statements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Documentary Evidence Rules

A
  1. Must be authenticated (testify)
  2. Best Evidence Rule
  3. Parol Evidence Rule
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Best Evidence Rule

A

Original documents are superior to copies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Parol Evidence Rule

A

Written contracts are assumed to be the entire agreement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Forms of Testimonial Evidence

A
  1. Direct - Witness provides evidence

2. Expert Opinion - Expert draws conclusions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Goal of Digital Forensics

A

Investigate techniques that collect, preserve, analyze, and interpret digital evidence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Volatility

A

Relative permanence of a piece of evidence; evidence that may not last long is more volatile than more permanent sources of evidence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Order of Volatility

A
  1. Network Traffic
  2. Memory Contents
  3. System and Process Data
  4. Files
  5. Logs
  6. Archive records
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Risk to transferring data during evidence?

A

That data will be added to device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Device used to prevent accidental modification of disks during imaging?

A

Write Blockers or Forensic Disk Controllers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is used to protect digital evidence from being tampered with?

A

Hashes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Flaw with Full Packet Capturing?

A

Requires a lot of storage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What does Netflow Capture?

A

High level info - IP addresses and ports; timestamps; amount of data transferred.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What devices capture Netflow data?

A

Routers and Firewalls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

2 Uses of Software Forensics

A

Intellectual Property & Malware Origin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Embedded Devices

A

Special-purpose computers found inside smart devices found in homes, businesses, and industrial settings.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What provides a paper trail for evidence?

A

Chain of Evidence OR Chain of Custody

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Evidence Log Events

A
  • Initial Collection
  • Transfer
  • Storage
  • Opening & Resealing the container
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Evidence Log Entry Details

A
  • Investigator Name
  • Date and Time
  • Purpose
  • Nature of Action
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

3 Components to Incident Reporting

A
  1. Notification
  2. Real Time Updates
  3. Documentation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Who must the Federal Government notify of Cybersecurity incidents?

A

US-CERT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What do Formal Incident Reports have?

A

Historical Documentation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

3 Major Steps in the Electronic Discovery Process

A
  1. Preservation - Litigation Hold & Suspending automatic deleting.
  2. Collection - Documents on file servers, endpoint servers, email messages, enterprise systems.
  3. Production - Documents provided to attorneys.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Litigation Hold

A

Require the preservation of relevant electronic and paper records.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Federal Law requires Businesses to report incidents to US-Cert?

A

No.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

During what phase of e-discovery does an organization share information with the other side?

A

Production

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Business Continuity Planning (BCP)

A

Set of controls designed to keep a business running in face of an adversity. Natural or man-made.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Business Continuity Plan is part of what core security concept?

A

Availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

BCP Scope

A

Business activities
Systems
Controls

39
Q

Tool used for BCP to help make the scoping decisions?

A

BIA - Business Impact Assessment.

40
Q

BIA

A

Business Impact Assessment

Identifies and prioritizes risks.

41
Q

Business Continuity Controls

A

Goal is Redundancy

42
Q

Single Point of Failure Analysis

A

ID’s and removes SPOFs

43
Q

What addresses the SPOF at the web server?

A

Clustering

44
Q

What addresses the SPOF at the Firewall?

A

HA FW

45
Q

What addresses the SPOF at the Network Level?

A

Redundancy Controls.

46
Q

SPOF analysis continues until when?

A

Cost of addressing risk outweighs the benefit.

47
Q

Two Key Technical Concepts that improve the availability of Systems.

A
  1. High Availability (HA)

2. Fault Tolerance (FT)

48
Q

HA

A

High Availability

Uses multiple systems to protect against service failure.

49
Q

FT

A

Fault Tolerance

Makes a single system resilient against technical failures.

50
Q

Difference between HA and FT

A

HA uses multiple systems to provide availability, whereas FT makes a single system more resilient.

51
Q

Load Balancing

A

Spreads demands across systems.

52
Q

Most common points of failure in a computer system

A
  1. Power Supply

2. Storage Media

53
Q

RAID

A

Redundant Array of Inexpensive Disks

Fault Tolerance Technique!

54
Q

2 Technologies used in RAID?

A

Mirroring - RAID 1 - Stores the Data on two different disks

Stripping - RAID 5 - Uses 3 or more disks to store data and parity information

55
Q

RAID 1

A

Store the same Data on two different disks.

Disk Mirroring

56
Q

RAID 5

A

Uses 3 or more disks to store data and parity information.

Disk Striping

57
Q

Disk Mirroring Requires how many disks?

A

2 - RAID 1

58
Q

Dis Striping with Parity requires how many disks?

A

3 or more - RAID 5

59
Q

RAID - Backup or Fault Tolerance?

A

FT

60
Q

QoS

A

Quality of Service

Provides critical services with protected network capacity.

61
Q

Disaster Recovery?

A

Restore a business to normal operations as quickly as possible.

It’s a subset of Business Continuity.

62
Q

Initial Responses in a DR?

A

Contain the damage caused

Recover whatever capabilities may be immediately restored.

Include a variety of activities depending upon the nature of the disaster.

63
Q

Components of Disaster Communications

A

Initial activation of the DR Team

Regular status updates

Tactical Communications

64
Q

After the danger passes, the team does what?

A

Shifts to assessment mode.

65
Q

Goal of assessment mode?

A

Triage the damage and develop plan to recover.

66
Q

Two metrics used to plan DR efforts.

A

RTO & RPO

67
Q

RTO

A

RECOVERY TIME OBJECTIVE

Maximum amount of time that is should take to recover a service after a disaster.

68
Q

RPO

A

RECOVERY POINT OBJECTIVE

Maximum time period from which data may be lost in the wake of a disaster.

69
Q

Responders do what after developing a plan?

A

Restore services in an orderly fashion

70
Q

When are DR efforts completed?

A

When the business is operation normally in its primary facility.

71
Q

Backups

A

Provide a data ‘safety net’.

72
Q

Backup Media Types

A

Tape Backups
Disk-to-disk backups
Cloud backups

73
Q

3 Type of Primary Backup Types

A

Full Backups - Include complete copy

Differential - Include all data since full backup

Incremental - Include all data data since full or Differential backup

74
Q

Difference between Incremental and Differential Backup?

A

Incremental Backup includes all data since last full or Differential backup.

Differential is all data since last full backup.

75
Q

Joe performs a full backup every Sunday evening and differential backups every weekday evening. This system fails on Wednesday, What backups does he need?

A
  1. Sunday’s Full Back (Base)

2. Wednesday’s Differential Backup

76
Q

Joe performs a full back every Sunday evening and incremental backups every weekday evening. His system fails on Friday morning. What backups does he need?

A
  1. Sunday’s Full Back Up (Base)
  2. Monday Incremental BU
  3. Tuesday IBU
  4. Wed IBU
  5. THR IBU
77
Q

Pros and Cons of Incremental Backups

A

Use less space

Require greater recovery time

78
Q

Media Rotation Strategies definition

A

Allow reuse of backup media

79
Q

Common Media Rotation Strategy?

A

GFS (Grandfather-Father-Son) Rotation

Son = Think of days
Fathers = Think of Weeks
Grandfather = think of months
80
Q

How to validate/test backups?

A

Built-in Back Up Verification (Validates backup completion)

Regularly Test Backups

81
Q

Ways to regularly test backups?

A

Request a file restoration from a random, yet specific point of time.

Request the restoration of a server or an entire service.

82
Q

DR Facility Types

A

Hot Site, Warm Site, Cold Site.

83
Q

Difference between DR Facility Types.

A

Hot - Full operational with equipment and data

Warm - Stocked with equipment and data, but not maintained in a parallel fashion.

Cold - Empty Data Centers

84
Q

Term for transferring data backup offsite digitally

A

Electronic Vaulting

85
Q

Goals of DR Testing Goals

A
  1. Validates that the plan functions correctly.

2. Identify necessary plan updates.

86
Q

Types of DR Testing

A
Read-through
Walk-through
Simulation
Parallel Test
Full Interruption Tests
87
Q

Read-Through

A

Type of DR Testing

Asks each member to review their role in the DR process and provide feedback.

88
Q

Walk - Through

A

Gathers the team together for a formal review of the DR plan.

Also known as a Table Top Exercise.

89
Q

Simulation

A

Uses practice scenario to test the DR Plan

90
Q

Parallel Test

A

Activates the DR Facility but do not switch operations there.

91
Q

Full Interruption

A

Activates the DR Facility and switches operations there.

92
Q

What disaster recovery metric provides the targets amount of time to restore a service after a failure?

A

RTO

93
Q

What type of backup includes only those files that have changed since the most recent full or incremental backup?

A

Incremental