Module 4 - 02-1 Flashcards
Phases of incident response playbooks
Define Playbook
A manual that provides details about any operational action,
clarify what tools should be used in response to a security incident,
and ensure that people follow a consistent list of actions in a prescribed way
Which statements are true about playbooks? Select three answers.
- Playbooks clarify what tools should be used to respond to security incidents.
- Playbooks categorize and analyze large amounts of data to help security teams identify risk.
- Playbooks are manuals that provide details about any operational action.
- Playbooks ensure that people follow a consistent list of actions in a prescribed way.
- Playbooks clarify what tools should be used to respond to security incidents.
- Playbooks are manuals that provide details about any operational action.
- Playbooks ensure that people follow a consistent list of actions in a prescribed way.
Playbooks are manuals that provide details about any operational action, clarify what tools should be used, and ensure people follow a consistent list of actions to address security incidents.
Define Living document
They are frequently updated by security team members to address industry changes and new threats
When how often would a playbook be updated (3)?
- A failure is identified, such as an oversight in the outlined policies and procedures, or in the playbook itself.
- There is a change in industry standards, such as changes in laws or regulatory compliance.
- The cybersecurity landscape changes due to evolving threat actor tactics and techniques.
What is are common playbooks used in cybersecurity?
- Incident response playbooks
- Vulnerability response playbooks
Define Incident response
An organization’s quick attempt to identify an attack, contain the damage, and correct the effects of a security breach
What is an Incident response playbook?
A guide with phases used to help mitigate and manage security incidents from beginning to end
How many phases does incident response playbook have?
Six (6)
What are the incident response playbook phases?
1) Preparation
2) Detection and analysis
3) Containment
4) Eradication and recovery
5) Post incident activity
6) Coordination
What is the (1st) first phase of an incident response playbook?
1) Preparation
What is the (2nd) second phase of an incident response playbook?
2) Detection and analysis
What is the (3rd) third phase of an incident response playbook?
3) Containment
What is the (4th) fourth phase of an incident response playbook?
4) Eradication and recovery
What is the (5th) fifth phase of an incident response playbook?
5) Post incident activity
What is the (6th) sixth phase of an incident response playbook?
6) Coordination