IRP_Incident_Management_Flashcards

1
Q

What is an Incident Response Plan (IRP)?

A

An IRP is a structured document outlining actions to detect, respond to, and limit the effects of cybersecurity incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of an IRP?

A

The IRP reduces the impact of incidents, ensures rapid response, and preserves organizational reputation by showing preparedness.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does an IRP assist in response escalation?

A

The IRP provides guidance for escalating responses based on incident severity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the role of policy creation in an IRP?

A

Policy creation defines guidelines and authorizes responders, outlining priorities but not specific procedures, which are covered in playbooks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the role of an Incident Response Team (IRT)?

A

The IRT, made up of technical, management, and legal representatives, coordinates incident handling and ensures effective communication with stakeholders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are playbooks in an IRP?

A

Playbooks are incident-specific guides that standardize responses, such as steps for handling ransomware attacks or data breaches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the importance of a communication strategy in an IRP?

A

It establishes clear communication channels for sharing incident details with internal and external stakeholders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why is testing the IRP important?

A

Regular testing (e.g., tabletop exercises) ensures team readiness, reveals gaps, and refines the IRP.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are key roles within a Cybersecurity Incident Response Team (CSIRT)?

A

Roles include Team Leader, Communications Specialist, Lead Investigator, Legal Advisor, and others like forensic analysts and threat researchers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the Team Leader do in the CSIRT?

A

The Team Leader coordinates response activities and provides updates to upper management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the responsibility of the Communications Specialist in the CSIRT?

A

The Communications Specialist manages internal and external communication, ensuring stakeholders receive accurate information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the role of the Lead Investigator in the CSIRT?

A

The Lead Investigator conducts in-depth investigations and provides threat intelligence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What role does the Legal Advisor play in the CSIRT?

A

The Legal Advisor ensures compliance with legal and regulatory standards during incident handling.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are benefits of a well-crafted IRP?

A

Benefits include reduced incident impact, minimized downtime, regulatory compliance, preserved reputation, and faster detection and response.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How does a well-crafted IRP reduce incident impact?

A

It enables early containment, helping to limit incident spread and damage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Why is regular updating of an IRP necessary?

A

To reflect changes in the IT environment and address emerging threats.

17
Q

What is the importance of a clear communication strategy in incident management?

A

It defines who to inform, what details to share, and the appropriate communication channels during incidents.

18
Q

What is incident closure in the IRP process?

A

Incident closure involves finalizing documentation, evaluating responses, and identifying improvements for future incidents.