Incident Response & Threat Management Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response & Threat Management flashcards as text
Which phase of the Cyber Kill Chain does spear-phishing with a malicious attachment PRIMARILY represent?
Answer: Delivery
Delivery is the phase where the adversary transmits the weaponized payload to the victim, such as via email attachment, link, or USB drop.
A CSIRT discovers an attacker established a scheduled task that runs every 15 minutes. This technique MOST directly maps to which MITRE ATT&CK sub-technique?
Answer: T1053.005 - Scheduled Task/Job: Scheduled Task
T1053.005 specifically covers Windows Scheduled Tasks used by adversaries for execution and persistence.
What is the PRIMARY advantage of using SOAR (Security Orchestration, Automation, and Response) during incident response?
Answer: It automates repetitive tasks to reduce mean time to respond
SOAR platforms automate playbook steps like IOC enrichment, ticket creation, and initial containment actions, significantly reducing MTTR.
During a tabletop exercise, team members disagree on who has authority to authorize taking a production database offline. Which document SHOULD resolve this?
Answer: Incident Response Plan's escalation and authority matrix
The IR Plan's authority matrix defines decision-making roles and escalation paths, including who can authorize disruptive containment actions.
An analyst observes a process making outbound connections to a rotating list of algorithmically generated domain names. This behavior MOST likely indicates:
Answer: Domain Generation Algorithm (DGA) malware C2
Domain Generation Algorithms produce large numbers of pseudo-random domains so malware can find its C2 even when individual domains are blocked.
Which chain-of-custody practice is MOST critical when collecting evidence from a live system during an IR investigation?
Answer: Documenting every action taken with timestamps and signing the evidence log
Detailed, timestamped documentation signed by investigators ensures evidence admissibility and demonstrates integrity in any subsequent legal proceedings.
After recovering from a supply chain attack via a compromised software update, which LONG-TERM control BEST prevents recurrence?
Answer: Implementing software composition analysis and code signing verification
Software composition analysis detects malicious or altered components, and code signing verification ensures updates come from legitimate, untampered sources.