โ† All CCST Flashcard Decks

Security Incident Handling Process Flashcards

6 cards from real CCST practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Security Incident Handling Process flashcards as text
  1. What is the first step in the NIST incident response lifecycle?

    Answer: Preparation

    Preparation involves establishing the CSIRT, creating policies, deploying tools, and conducting training.

  2. What is the difference between short-term and long-term containment?

    Answer: Short-term stops immediate damage; long-term implements sustainable controls during investigation

    Short-term: rapid actions to stop spread. Long-term: sustainable controls allowing continued operations during investigation.

  3. Why is maintaining chain of custody important during incident handling?

    Answer: To ensure digital evidence is properly documented, preserved, and admissible in legal proceedings

    Chain of custody documents every handler of evidence, ensuring integrity and court admissibility.

  4. What is the purpose of the eradication phase?

    Answer: To completely remove the threat and its artifacts from all affected systems

    Eradication removes all malware, backdoors, and unauthorized changes, and patches exploited vulnerabilities.

  5. What should a lessons learned meeting focus on after an incident?

    Answer: Analyzing what happened, what worked, what could improve, and how to prevent recurrence

    Post-incident review evaluates response effectiveness and produces actionable improvements.

  6. What role does a SIEM play in incident detection?

    Answer: It collects, correlates, and analyzes log data from multiple sources to identify potential incidents

    SIEM aggregates logs from across the network, correlates events using rules, and generates alerts for potential incidents.

Security Incident Handling Process Flashcards โ€” CCST Study Cards with Answers