Incident Response Flashcards

1
Q

Step 1

A

Detection: An alert indicates unusual outbound traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Step 2

A

Containment: Disconnect affected machines and block suspicious domains.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Step 3

A

Eradication: Identify malware, remove it, and patch the vulnerability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Step 4

A

Recovery: Restore systems from backups and monitor for lingering threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Step 5

A

Post-Incident Review: Analyze the incident, update policies, and train employees.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly