CAP Incident Response & Recovery 3 — Questions and Answers
Question 1: Which role within an incident response team is responsible for coordinating communications with external parties such as law enforcement and the media?
- Incident Handler
- Technical Lead
- Public Affairs Officer / Liaison (Correct answer)
- System Owner
Correct answer: Public Affairs Officer / Liaison
The Public Affairs Officer or Liaison manages external communications including media, law enforcement, and other stakeholders during an incident.
Question 2: Under FISMA, an agency experiences a breach of PII affecting 5,000 individuals. What additional reporting requirement is triggered?
- Report to Congress within 7 days
- Notify affected individuals and potentially US-CERT within strict timelines (Correct answer)
- Immediately shut down all affected systems
- File a report with GAO within 30 days
Correct answer: Notify affected individuals and potentially US-CERT within strict timelines
Breaches of PII trigger mandatory notification to affected individuals and US-CERT reporting under OMB guidelines and agency privacy policies.
Question 3: What is the purpose of a 'jump bag' in incident response?
- A portable kit of tools and documentation ready for immediate incident response deployment (Correct answer)
- A secure container for storing encryption keys
- A database of known threat indicators
- A backup set of authentication credentials
Correct answer: A portable kit of tools and documentation ready for immediate incident response deployment
A jump bag is a pre-packed collection of hardware, software, and documentation that responders can grab immediately when deploying to handle an incident.
Question 4: During post-incident analysis, a team discovers the attack exploited an unpatched vulnerability. According to NIST SP 800-61, this finding should primarily feed into:
- The incident log archive
- The lessons learned report and remediation plan (Correct answer)
- The next incident response drill
- The system decommission plan
Correct answer: The lessons learned report and remediation plan
Post-incident analysis findings, especially root cause identification, should be documented in the lessons learned report and drive concrete remediation actions.
Question 5: Which type of incident response team model is most appropriate for a large federal agency with geographically dispersed offices?
- Centralized team
- Distributed team (Correct answer)
- Coordinating team
- Outsourced team
Correct answer: Distributed team
A distributed team model places incident handlers at multiple geographic locations, making it better suited for large agencies with dispersed operations.
Question 6: In Business Continuity Planning (BCP), what distinguishes a Recovery Time Objective (RTO) from a Recovery Point Objective (RPO)?
- RTO measures data loss tolerance; RPO measures system downtime
- RTO is the maximum acceptable downtime; RPO is the maximum acceptable data loss (Correct answer)
- RTO applies to hardware; RPO applies to software
- RTO is set by leadership; RPO is set by the security team
Correct answer: RTO is the maximum acceptable downtime; RPO is the maximum acceptable data loss
RTO defines how quickly systems must be restored after disruption, while RPO defines how much data loss (measured in time) is acceptable.
Question 7: A CAP professional is reviewing an Incident Response Plan (IRP). Which element is MOST critical to verify is current and accurate?
- List of software versions in use
- Contact information for the incident response team and escalation paths (Correct answer)
- Network diagram from the previous year
- Historical log of past incidents
Correct answer: Contact information for the incident response team and escalation paths
Outdated contact information and escalation paths are among the most common reasons IRPs fail during actual incidents, making this the most critical element to keep current.
Which role within an incident response team is responsible for coordinating communications with external parties such as law enforcement and the media?