Incident Response Flashcards

1
Q

Which plan disscusses cold sites and recovery point objectives

A

Disaster Recovery Plans

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What plan is this?

  1. Providing continuity of the orgs operations
  2. Improved protection of the orgs assets
    3.Enhanced physical and data security
  3. Reduced insurance costs
A

Disaster recovery plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

At what stage do you gather information about an incident?

A

Observe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

At what stage do you analyze the info you have gathered and assess the situation

A

Orient

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What tools would be included in the “Observe” category of the OBserve-Orient-Decide- Act (OODA) Loop?

A

Security information and event management
Intrusion detection systems
Netflow analyzers
Vulnerability scanners
Availability monitoring
Web proxies

The observe category includes security monitoring tools identifying events that might need further investigation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly