Incident_Response_And_Forensics_Flashcards

1
Q

What are the key stages of Incident Response?

A

Preparation, detection, containment, eradication, and recovery.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of an Incident Response Plan (IRP)?

A

To provide a documented set of procedures for responding to cybersecurity incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who is responsible for detecting, responding to, and mitigating cybersecurity incidents?

A

The Incident Response Team (IRT).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the key components of digital forensics?

A

Collecting, preserving, and analyzing digital evidence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why is digital forensics important in legal proceedings?

A

To provide evidence for court cases and ensure its admissibility by maintaining integrity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the first stage of Incident Response?

A

Preparation, which involves establishing policies and conducting risk assessments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Why is the detection stage critical in Incident Response?

A

It allows for quick response and prevention of further damage by identifying suspicious activities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does containment aim to achieve in Incident Response?

A

It isolates affected systems to prevent the spread of an incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How does digital forensics help in incident response?

A

It uncovers the who, what, when, where, and how of a cyber incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a forensic image in digital forensics?

A

A bit-by-bit copy of storage media used to preserve original data for analysis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly