Incident Response Flashcards

1
Q

Intelligent Alert Triage and Prioritization

A

Categorize and prioritize alerts based on severity, type of threat, and potential impact using generative AI, ensuring that the most critical issues are addressed first.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Containment Procedures

A

Automatically execute actions to contain a threat, such as isolating affected systems, blocking malicious IP addresses, or reconfiguring network access controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat Remediation

A

Implement remediation steps to eliminate threats, such as applying patches, updating firewall rules, re-configuring cloud applications, or removing malware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Incident Notification Procedures

A

Automatically notify relevant stakeholders, including SOC analysts, IT staff, management, and potentially affected users, about a security incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Threat Intelligence Updates

A

Dynamically update threat intelligence feeds and apply new indicators of compromise (IoCS) to security tools based on updated information from incidents and investigations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Evidence Preservation

A

Automatically collect and preserve digital evidence for further investigation and potential legal proceedings. A full audit log of all automated actions performed is logged within the case management solution.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly