Incident management Flashcards
1
Q
Explain the key steps of an effective incident response process
A
detection, identification, containment, eradication, recovery, and lessons learned
2
Q
Describe how you would approach a post-incident review (PIR)
A
- understand the incident’s scope, impact, and contributing factors
- use the “Five Whys” technique to delve into deeper causes and identify systemic issues
3
Q
How would you define severity levels and response times
A
- levels should be defined based on the impact an incident has on users, revenue, reputation, etc.
- common levels: critical, high, medium, low
- response times should correspond to severity
4
Q
What roles are outlined in the “Incident Command System” (ICS)?
A
Incident Commander, Communication Liaison, and Technical Experts