Unit 2 - Module 4 Flashcards

1
Q

Define Playbook

A

A manual that provides details about any operational action.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does Incident response mean?

A

Incident response is an organization’s quick attempt to identify an attack, contain the damage, and correct the effects of a security breach.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the 6 Incident responses in the playbook phase?

A

1) Preparation
2) Detection and analysis
3) Containment
4) Eradication and recovery
5) Post incident activity
6) Coordination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Playbooks sometimes cover what 2 specific things?

A

Incidents and Vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Define the Preparation phase (1)

A

Before incidents occur, mitigate potential impacts on the organization by documenting, establishing staffing plans, and educating users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Define the Detection and analysis phase (2)

A

Detect and analyze events by implementing defined processes and appropriate technology.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Define the Containment phase (3)

A

Prevent further damage and reduce immediate impact of incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Define the Eradication and recovery phase (4)

A

Completely remove artifacts of the incident so that an organization can return to normal operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Define the Post-incident activity phase (5)

A

Document the incident, inform organizational leadership, and apply lessons learned.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Define the Coordination phase (6)

A

Report incidents and share information throughout the response process, based on established standards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What can playbooks be used for? ( What kind of incidents, leaks and attacks ) 5 Examples

A

Open attacks
Privacy incidents
Data leaks
Denial of service attacks
Service alerts
Others

How well did you know this?
1
Not at all
2
3
4
5
Perfectly