Incident Response Procedures Flashcards

1
Q

What what is occurring when an investigator follows a set of procedures after a computer security incident?

A

Incident Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What do you call the overall program, regarding the response to a computer security event?

A

Incident Management Program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the six steps in an Incident Response?

A
Preparation
Identification
Containment
Eradication
Recovery
Lessons Learned

Exam Tip: You must know exactly the order of these steps, and what they are

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Explain the general idea of the preparation phase

What step is this?

A

Having a well planned incident response procedure.
Having a strong security posture.
Having a knowledgeable chief information security officer.

Step 1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What step of incident response is determining that if an event should be elevated to an incident status?

What step is this?

A

Identification

Step 2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What step of incident response is focused on isolating the incident?

What step is this?

A

Containment

Step 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What step of incident response is focused on removing the threat or attack?

What step is this?

A

Eradication

Step 4

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What step of incident response is focused on data restoration, system repair, and bringing the network/servers back online?

What step is this?

A

Recovery

Step 5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What step of incident response is focused on learning from the incident?

What step is this?

A

Lessons Learned

Step 6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly