Incident Response Flashcards

1
Q

What is the OODA Loop?

A
  • “Observe, Orient, Decide, Act”
  • Organizations use OODA loop to determine which incident response tools to use.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What tools are in the Observe category of the OODA Loop?

A
  • Intrusion detection systems
  • Vulnerability scanners
  • Availability monitoring
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 4 phases of an incident response plan?

PLEASE DON’T COME PLEASE

A

1) Planning
2) Detection and analysis
3) Containment, eradication, and recovery
4) Post-incident review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a cybersecurity EVENT?

A
  • It is a singular occurrence of a change in a system or network.
  • Examples include: network scans and failed login attempts that are stopped before the system is compromised.
  • The change in network may come from inside or outside the organization and may result from normal operation, error, or fraud.
  • It’s NOT a malicious or evil thing!
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a cybersecurity INCIDENT?

A
  • It involves a violation of security policies, procedures, or acceptable use policies.
  • It has a negative effect on the confidentiality, integrity, or availability of an organization’s data or systems.
  • There is MALICIOUS INTENT and EVIL here!
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a post-incident analysis of a security incident?

A

It is an analysis that is part of an advisory (consulting) engagement and is done in order to develop recommendations for decision making

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are 3rd party losses?

A

They are losses suffered by customers and business partners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the job of an incident response manager?

A
  • His job is to oversee all incident response team activity.
  • This activity includes the detection, analysis, and containment of an incident.
  • Communicate incident response requirements to relevant stakeholders
  • Test the incident response plan at least annually
  • Take corrective action when the incident response plan is not followed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What responsibility does an incident response manager have?

A
  • Communicate incident response requirements to relevant stakeholders
  • Declare when an incident has occurred
  • Test the incident response plan annually
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why should an incident response plan include the organization’s cybersecurity insurance policy number/info?

A
  • Because an insurance policy transfers the risk of loss to the insurance company in exchange for insurance premiums.
  • Cybersecurity insurance covers 1st party losses (costs incurred directly by the organization) and 3rd party losses (liabilities owed to external people).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which group selects members for the incident handling and incident response teams?

A

Senior management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the 3 staffing models for incident response plans?

A
  • In-house staffed
  • Partially outsourced
  • Fully outsourced
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How can internal and external auditors evaluate if an entity responded to cybersecurity incidents?

A

They can do so in accordance with a documented incident response plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are goals of incident response plans?

A

To ensure proper reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are some pre-incident services offered by cybersecurity insurance companies?

A
  • Self-assessments
  • Online training
  • Consultations
  • Incident response planning
How well did you know this?
1
Not at all
2
3
4
5
Perfectly