Incident Response Procedures Flashcards
What what is occurring when an investigator follows a set of procedures after a computer security incident?
Incident Response
What do you call the overall program, regarding the response to a computer security event?
Incident Management Program
What are the six steps in an Incident Response?
Preparation Identification Containment Eradication Recovery Lessons Learned
Exam Tip: You must know exactly the order of these steps, and what they are
Explain the general idea of the preparation phase
What step is this?
Having a well planned incident response procedure.
Having a strong security posture.
Having a knowledgeable chief information security officer.
Step 1
What step of incident response is determining that if an event should be elevated to an incident status?
What step is this?
Identification
Step 2
What step of incident response is focused on isolating the incident?
What step is this?
Containment
Step 3
What step of incident response is focused on removing the threat or attack?
What step is this?
Eradication
Step 4
What step of incident response is focused on data restoration, system repair, and bringing the network/servers back online?
What step is this?
Recovery
Step 5
What step of incident response is focused on learning from the incident?
What step is this?
Lessons Learned
Step 6