Lesson 12 -- Verified Flashcards

1
Q

SECURITY INCIDENT

A

INSTANCE OF A RISK EVENT OCCURRING

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Does a security incident have to cause damage

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security Incident Management

A

Practices and procedures that govern how an organization will respond to an incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the goal of incident management

A

Contain the incident

Minimize the damage

Includes procedures to log, report on and the actions taken in the response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

IRP

A

Incident Response Policy

  • Who determines and declares if an incident occurred
  • Who will be notified
  • How and When they will be notified
  • Guidelines for the appropriate response
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a first responder

A

Experienced personnel that arrives on the scene of the incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is change management

A

A systematic way of approving and executing change in order to ensure max security, stability, and availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An organization must be able to for incidents

A

Properly assess risk

Quantify cost of training

Support

Maintenance

Weigh the benefits of the proposed change

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A forensics process should

A

Inform responders how to properly investigate an incident to avoid legal issues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the basic forensic process

A

First responders arrive

Secure the area

Document the scene

Perform eDiscovery

Collect any other evidence and data

Preserve the chain of custody

Have proper data transport procedures

Report you forensic findings

Follow legal hold procedures if needed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Name some ways of securing a physical location

A

Put up signs

Lock doors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Name some ways of securing a digital location

A

Take the system offline

Put the single device in a secure location

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who should start documenting the scene

A

First Responders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is eDiscovery

A

Electronic aspect of identifying, collecting, and producing electronically stored information in response to a request in a lawsuit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ESI

A

Electronically Stored Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Should you consult a lawyer before collecting information

A

Yes

Always use professionals when collecting digital information

17
Q

Chain of Custody

A

Tracking evidence from the time it is collected until it is released back to the owner

Use a chain of custody document

18
Q

Digital information can be altered and should be transported on an encrypted drive

A

True

19
Q

Forensic Report

A

Summarizes the substantive evidence

Details the steps performed to acquire and analyze the data

20
Q

Legal Hold

A

Process to preserve all forms of relevant information when litigation is anticipated

Audits/investigation/Litigation

21
Q

Complete

A

Complete