Incident Response Process (OBJ 4.8) Flashcards
1
Q
7 Step of Incident Response
A
- Preparation
- Detection
- Analysis
- Containment
- Eradication
- Recovery
- Post-Incident Activity/ Lesson Learned
2
Q
Preparation Phase
A
Policy, standard, training, testing and exercises of simulated incidents
3
Q
Detection Phase
A
Identifies security incident
4
Q
Analysis Phase
A
- Involves a thorough examination and evaluation of the incident.
- Stakeholders are notified
- containment begins
- initial response actions are taken.
5
Q
Containment
A
Limit the scope and magnitude of the incident by securing data and protecting business operations.
6
Q
Eradication
A
Starts after containment and aims to remove malicious activity from the system network.
7
Q
ctivit
A
8
Q
Penetration Testing tools
A
Metabolites
Cobalt Strike
Kali Linux
ParrotOS
Commando OS
9
Q
A