IS4670 Chapter 13 Incident and Intrusion Response Flashcards
1
Q
- The ideal time for an organization to learn how to respond to security incidents is after suffering an attack.
A. True
B. False
A
FALSE
2
Q
- It is impossible to prevent all security incidents. Therefore, when a security incident does occur, an organization must ________ its impact.
A
Minimize
3
Q
3. Which of the following is a violation of computer security policies, acceptable use policies, or standard security practices? A. Event B. Adverse event C. Computer security incident D. US-CERT
A
Computer security incident
4
Q
- The ideal incident response team membership and structure depends on the type of organization and its risk management strategy.
A. True
B. False
A
TRUE
5
Q
5. An incident response team should place all emergency system information in a central, offline location. Which of the following is not a type of information that falls into this category? A. Malicious code B. Administrative passwords C. Network layout diagrams D. Router configuration information E. Firewall configuration information
A
Malicious code
6
Q
6. Which member of an incident response team is responsible for a particular incident or set of related security incidents? A. Team leader B. Incident lead C. Associate member D. Chief information officer
A
Incident lead
7
Q
- The incident response team performs most actions in response to an incident. However, all levels of IT staff should be aware of how to report incidents internally.
A. True
B. False
A
FALSE
8
Q
- An organization’s ________ outlines specific procedures to follow in the event of a security incident.
A
Incident response plan
9
Q
- An organization should try to let attackers know that the organization is aware of their activities.
A. True
B. False
A
FALSE
10
Q
- ________ assists federal civilian agencies in their incident-handling efforts. It analyzes the information provided by all agencies to identify trends and precursors of attacks.
A
US-CERT
11
Q
- When an organization is determining the damage it has sustained, it should consider both ________ and ________ costs.
A
Direct, Indirect