Domain 7 Flashcards

1
Q

NIST 800-86 Covers What?

A

Digital Forensics Process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Steps of Digital Forensics

A
  1. Collection
  2. Examination
  3. Analysis
  4. Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What forensics is prioritized to collect

A

volatile data to most stable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Forensics Process is Covered in which document

A

NIST SP-800-86

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

3 P’s of Incident Response

A

Policy
Plan
Procedures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Phases of Incident Response Handling

A
  1. Preparation
  2. Detection and Analysis
  3. Containment, Eradication, Recovery
  4. Post incident activity (Lessons Learned)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Steps of Change Management

A
  1. Change Request (documented)
  2. Evaluate (prioritize) and test
  3. Rollback Procedure
  4. Change Control Board Review and approval(standard changes can be pre-authorized)
  5. Change window/implemented
  6. Document updated change
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

MTBF

A

Medium Time Before Failure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

MTTR

A

Medium Time To Recover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Software Escrow

A

Source Code is put into a third party trust that maintains it. If the developing person or company ends, the escrow can be released to company.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Load balancing

A

Server Cluster, will fail over to another server if one fails

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Who manages a DR

A

DR Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who communicates with Media

A

No one, except for CEO or designated person per policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

RTO

A

Recovery Time Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Define RTO

A

The amount of time planned to recover in the event of a DR or outage. (i.e. 30 minutes, or 30 days)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Steps for DRP

A
  1. Policy Statement
  2. BIA
  3. Plan of Action
  4. Test, Train, and Maintain