Incident Handling Flashcards
What is a comprehensive incident report completed on all CAT I, II, IV and VIIs
AFCIR (AF Cyber Incident Report)
Category 1
Root Level
Explained Anomaly
Event
User Level
Incident
Investigating
Event
What are the Mission Assurance Categories (MACs)
MAC I, II, III
What are the phases contained in the standard AF incident response process
Preparation, Detection, Isolation & Containment, Secure, Recover, Lessons Learned
What incident response phase sees 90% accomplished when the system is removed from the network
Isolation and Containment
What MAC says the system is IMPORTANT to the support of deployed forces
MAC level II
What incident response phase sees Operational & technical impact assessed
Secure
Category 4
Denial Of Service
Category 6
Reconnaisance
Category 8
Investigating
What incident response phase sees advanced forensic analysis, malware submitted to AV vendors, software vendors notified of exploited vulnerabilities
Secure
What incident response phase sees Signatures Developed
Secure
Who produces/disseminates the AFCIR
33rd NWS
What incident response phase sees the SysPOC completed
Secure
What incident response phase sees New TTP potentially incorporated into authorized procedures
Lessons Learned
Of the 9 CAT events, which one is User Level Intrusion
CAT II: (Incident)
Of the 9 CAT events, which one is Unsuccessful Activity Attempt
CAT III: (Event)
What MAC says the system is VITAL to operational readiness or mission effectiveness of deployed forces
MAC level I
Of the 9 CAT events, which one is NON-COMPLIANCE Activity/Poor Security Practice
CAT V: (Event)
Reconnaisance
Event