Quiz: Module 05 Flashcards

1
Q

The first step in building a CSIRT is to ____.
a. obtain management support and buy-in
b. design the CSIRT vision
c. determine the CSIRT strategic plan
d. gather relevant information

A

a. obtain management support and buy-in

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

An organization that provides security services to client organizations, often remotely, including incident monitoring, response, and recovery is known as a _____.
a. managed security service provider
b. management security source partner
c. multiple service security provider
d. managed service security provider

A

a. managed security service provider

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The determination of what systems fall under the CSIRT ‘s responsibility is called its ____.
a. constituency
b. scope of operations
c. mission
d. policy

A

b. scope of operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Giving the IR team the responsibility for ____ is generally not recommended.
a. incident analysis
b. patch management
c. vulnerability assessment
d. advisory distribution

A

b. patch management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The focus during a(n) ____ is on learning what worked, what didn’t, and where communications and response procedures may have failed.
a. after-action review
b. incident response
c. CSIRT resource meeting
d. advisory distribution

A

a. after-action review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In some organizations, the computer security incident response team (CSIRT) may simply be a loose or informal association of IT and InfoSec staffers who are called if an attack on the organization’s information assets is detected.
a. True
b. False

A

a. True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The final step in the development of the CSIRT involves obtaining management support and buy-in.
a. True
b. False

A

b. False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A managed security service provider is an organization that provides limited security services to client organizations, usually just offsite backup services.
a. True
b. False

A

b. False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

As soon as the CSIRT is able to determine what exactly is happening, it is expected to report its preliminary finding to management.
a. True
b. False

A

a. True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Communicating the CSIRT’s vision and plan begins with the managerial team or individual serving as champion.
a. True
b. False

A

a. True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly