Incident Response Flashcards
1
Q
Which plan disscusses cold sites and recovery point objectives
A
Disaster Recovery Plans
2
Q
What plan is this?
- Providing continuity of the orgs operations
- Improved protection of the orgs assets
3.Enhanced physical and data security - Reduced insurance costs
A
Disaster recovery plan
3
Q
At what stage do you gather information about an incident?
A
Observe
4
Q
At what stage do you analyze the info you have gathered and assess the situation
A
Orient
5
Q
What tools would be included in the “Observe” category of the OBserve-Orient-Decide- Act (OODA) Loop?
A
Security information and event management
Intrusion detection systems
Netflow analyzers
Vulnerability scanners
Availability monitoring
Web proxies
The observe category includes security monitoring tools identifying events that might need further investigation.