Quiz: Module 05 Flashcards
The first step in building a CSIRT is to ____.
a. obtain management support and buy-in
b. design the CSIRT vision
c. determine the CSIRT strategic plan
d. gather relevant information
a. obtain management support and buy-in
An organization that provides security services to client organizations, often remotely, including incident monitoring, response, and recovery is known as a _____.
a. managed security service provider
b. management security source partner
c. multiple service security provider
d. managed service security provider
a. managed security service provider
The determination of what systems fall under the CSIRT ‘s responsibility is called its ____.
a. constituency
b. scope of operations
c. mission
d. policy
b. scope of operations
Giving the IR team the responsibility for ____ is generally not recommended.
a. incident analysis
b. patch management
c. vulnerability assessment
d. advisory distribution
b. patch management
The focus during a(n) ____ is on learning what worked, what didn’t, and where communications and response procedures may have failed.
a. after-action review
b. incident response
c. CSIRT resource meeting
d. advisory distribution
a. after-action review
In some organizations, the computer security incident response team (CSIRT) may simply be a loose or informal association of IT and InfoSec staffers who are called if an attack on the organization’s information assets is detected.
a. True
b. False
a. True
The final step in the development of the CSIRT involves obtaining management support and buy-in.
a. True
b. False
b. False
A managed security service provider is an organization that provides limited security services to client organizations, usually just offsite backup services.
a. True
b. False
b. False
As soon as the CSIRT is able to determine what exactly is happening, it is expected to report its preliminary finding to management.
a. True
b. False
a. True
Communicating the CSIRT’s vision and plan begins with the managerial team or individual serving as champion.
a. True
b. False
a. True