Security Incident Handling Process Flashcards
6 cards from real CCST practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Security Incident Handling Process flashcards as text
Which of the following activities is a critical component of the 'Preparation' phase of the security incident handling process, according to the NIST framework?
Answer: Establishing and training a Computer Security Incident Response Team (CSIRT).
The 'Preparation' phase involves all the proactive steps taken before an incident occurs to ensure the organization is ready to respond. Establishing and training a CSIRT is a fundamental preparatory step, along with creating policies, acquiring necessary tools, and performing risk assessments.
A support technician observes alerts from a SIEM tool indicating multiple failed login attempts on a critical server, followed by a successful login from an unrecognized IP address. Which phase of the incident handling process has just begun?
Answer: Detection and Analysis
The 'Detection and Analysis' phase begins when potential signs of an incident are discovered. This involves detecting anomalies (the alerts) and then analyzing them to determine if a security incident has actually occurred, which is the immediate next step for the technician.
During a malware outbreak, a security analyst instructs a technician to immediately disconnect the infected computers from the corporate network. This action is a primary example of which incident response phase?
Answer: Containment
Containment strategies are actions taken to stop the incident from causing further damage and to prevent it from spreading to other systems. Disconnecting affected machines is a classic short-term containment step to isolate the threat.
After a security incident has been contained and the immediate threat is neutralized, a technician is tasked with re-imaging an affected workstation from a known good gold image and ensuring all security patches are applied. This activity belongs to which two connected phases of the incident response lifecycle?
Answer: Eradication and Recovery
This action serves two purposes. 'Eradication' involves removing the root cause of the incident (the malware is wiped out by re-imaging). 'Recovery' involves restoring the affected systems back to normal operation so business can resume, which includes applying patches to prevent reinfection.
A company has just recovered from a major data breach. The management team holds a meeting with the IT and security staff to review the incident timeline, discuss what went well, identify weaknesses in the response, and update the incident response plan. In which phase of the incident handling process does this activity occur?
Answer: Post-Incident Activity (Lessons Learned)
The Post-Incident Activity, or Lessons Learned, phase is a critical final step where the team analyzes the incident and the response to it. The goal is to improve security controls and the incident handling process itself to prevent or better handle future incidents.
According to the NIST SP 800-61 incident response lifecycle, what is the correct sequence of the major phases?
Answer: Preparation, Detection and Analysis, Containment/Eradication/Recovery, Post-Incident Activity
The widely adopted NIST incident response lifecycle follows a logical progression: first, you prepare for incidents; then you detect and analyze them; next, you contain, eradicate, and recover from them; and finally, you conduct post-incident activities to learn from the event.