Incident Response Flashcards

1
Q

After eradicating threats using the IRP, which step is done next?

  • Patch vulnerable systems
  • Verify that the threat has been eradicated
  • Update the IRP
  • Generate an incident summary report
A

Verify that the threat has been eradicated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

You are updating the incident response plan (IRP) for an automated assembly line process. Which IRP component will facilitate speedy escalations when needed?

  • Definition of terms
  • Communication plan
  • Revision history
  • Eradication procedures
A

Communication plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

After eradicating and verifying a malware outbreak on the network, you perform a post-incident analysis to determine how quickly the IRP was applied. Which metric should you analyse?

  • Disk read bytes
  • Mean time to respond
  • Recovery time objective
  • Disk write bytes
A

Mean time to respond

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are incident response plans that strive to return disrupted systems to a functional state quickly said to adhere to?

  • SLA
  • RTO
  • GDPR
  • RPO
A

RTO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the primary purpose of incident containment?

  • Eradication
  • Patching
  • Report generation
  • Prevent spread
A

Prevent spread

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which type of Microsoft Azure resource can automate incident response without writing code?

  • Logic app
  • Workspace
  • Virtual machine
  • Function app
A

Logic app

How well did you know this?
1
Not at all
2
3
4
5
Perfectly