Lecture 8 Flashcards

1
Q

What are the key phases of Incident Response?

A

The key phases are Preparation, Detection and Analysis, Containment, Eradication, Recovery, and Post-Incident Activity, each critical for effective incident management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why is the Preparation phase important in Incident Response?

A

Preparation ensures that the SOC has the necessary tools, processes, and plans in place to respond effectively to incidents, minimizing impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the role of Detection and Analysis in Incident Response?

A

Detection and Analysis involve identifying potential incidents and understanding their scope and impact, which is crucial for determining appropriate response actions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the goal of the Containment phase in Incident Response?

A

The goal is to limit the spread and impact of an incident, preventing further damage and stabilizing the situation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is achieved during the Eradication phase of Incident Response?

A

Eradication involves removing the threat from the environment, including deleting malware, closing vulnerabilities, and ensuring no residual risk remains.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Why is Recovery important in Incident Response?

A

Recovery focuses on restoring normal operations and ensuring systems are secure and fully functional after an incident has been resolved.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the purpose of Post-Incident Activity in Incident Response?

A

Post-Incident Activity involves analyzing the incident to learn from it and improve future response strategies, including updating policies and procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do Playbooks benefit Incident Response?

A

Playbooks provide predefined, step-by-step procedures for responding to specific types of incidents, ensuring a consistent and efficient response.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the value of automation in Incident Response?

A

Automation speeds up response times, reduces human error, and allows SOC staff to focus on more complex tasks, improving overall efficiency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the difference between reactive and proactive Incident Response?

A

Reactive Incident Response deals with incidents after they occur, while proactive Incident Response involves preparing and mitigating potential incidents before they happen.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How do playbooks ensure compliance with regulatory frameworks?

A

By standardizing incident response processes, playbooks help ensure that responses are consistent with regulatory requirements and best practices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Why is collaboration important in Incident Response?

A

Collaboration ensures that all relevant teams and stakeholders are involved in the response, providing diverse expertise and resources for resolving incidents effectively.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the role of Key Performance Indicators (KPIs) in Incident Response?

A

KPIs measure the effectiveness and efficiency of incident response efforts, helping to identify areas for improvement and demonstrate the value of security investments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is an example of a task ideal for automation in Incident Response?

A

Identity and access management, such as automatically disabling compromised accounts, is an example of a task that benefits from automation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How do playbooks improve the Incident Response program?

A

Playbooks provide a structured approach to incident response, ensuring that responses are consistent, predictable, and measurable, leading to better outcomes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly