Incident Response Flashcards
After eradicating threats using the IRP, which step is done next?
- Patch vulnerable systems
- Verify that the threat has been eradicated
- Update the IRP
- Generate an incident summary report
Verify that the threat has been eradicated
You are updating the incident response plan (IRP) for an automated assembly line process. Which IRP component will facilitate speedy escalations when needed?
- Definition of terms
- Communication plan
- Revision history
- Eradication procedures
Communication plan
After eradicating and verifying a malware outbreak on the network, you perform a post-incident analysis to determine how quickly the IRP was applied. Which metric should you analyse?
- Disk read bytes
- Mean time to respond
- Recovery time objective
- Disk write bytes
Mean time to respond
What are incident response plans that strive to return disrupted systems to a functional state quickly said to adhere to?
- SLA
- RTO
- GDPR
- RPO
RTO
What is the primary purpose of incident containment?
- Eradication
- Patching
- Report generation
- Prevent spread
Prevent spread
Which type of Microsoft Azure resource can automate incident response without writing code?
- Logic app
- Workspace
- Virtual machine
- Function app
Logic app