Operations and Incident Response Flashcards

1
Q

What analysis framework provides the most explicit detail regarding how to mitigate or detect a given threat?

A

The MITRE ATT&CK framework

Explanation - The MITRE ATT&CK framework provides explicit pseudo-code examples for how to detect or mitigate a given threat within a network and ties specific behaviors back to individual actors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What platform utilizes a well-written set of carefully developed and tested scripts to orchestrate runbooks and generate consistent server builds across an enterprise?

A

Infrastructure as Code (IaC)

Explanation - IaC is designed with the idea that a well-coded description of the server/network operating environment will produce consistent result across an enterprise, and significantly reduce IT overhead costs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What should be used as a checklist of actions to perform in order to detect and respond to an ongoing spearphishing campaign against an organization?

A

A “Playbook” is a checklist of actions to perform to detect and respond to a specific type of incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What practices should be implemented to ensure that none of its computers can run a peer-to-peer file sharing program on an office environment?

A

Application Blacklisting

Explanation - Implementing this practice will block and limit the number of known programs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the correct order for the Incident Response process?

A
  • Preparation
  • Identification
  • Containment
  • Eradication
  • Recovery
  • Lessons Learned
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What action should be done FIRST after forensically imaging a hard drive for evidence in an investigation?

A

Create a hash digest of the source drive and the image file to ensure both match

How well did you know this?
1
Not at all
2
3
4
5
Perfectly