Incident Response Process (OBJ 4.8) Flashcards

1
Q

7 Step of Incident Response

A
  1. Preparation
  2. Detection
  3. Analysis
  4. Containment
  5. Eradication
  6. Recovery
  7. Post-Incident Activity/ Lesson Learned
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Preparation Phase

A

Policy, standard, training, testing and exercises of simulated incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Detection Phase

A

Identifies security incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Analysis Phase

A
  • Involves a thorough examination and evaluation of the incident.
  • Stakeholders are notified
  • containment begins
  • initial response actions are taken.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Containment

A

Limit the scope and magnitude of the incident by securing data and protecting business operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Eradication

A

Starts after containment and aims to remove malicious activity from the system network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

ctivit

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Penetration Testing tools

A

Metabolites
Cobalt Strike
Kali Linux
ParrotOS
Commando OS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly