Incident management Flashcards

1
Q

Explain the key steps of an effective incident response process

A

detection, identification, containment, eradication, recovery, and lessons learned

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Describe how you would approach a post-incident review (PIR)

A
  • understand the incident’s scope, impact, and contributing factors
  • use the “Five Whys” technique to delve into deeper causes and identify systemic issues
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How would you define severity levels and response times

A
  • levels should be defined based on the impact an incident has on users, revenue, reputation, etc.
  • common levels: critical, high, medium, low
  • response times should correspond to severity
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What roles are outlined in the “Incident Command System” (ICS)?

A

Incident Commander, Communication Liaison, and Technical Experts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly