Security Incident Handling Process Flashcards
6 cards from real CCST practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Security Incident Handling Process flashcards as text
What is the first step in the NIST incident response lifecycle?
Answer: Preparation
Preparation involves establishing the CSIRT, creating policies, deploying tools, and conducting training.
What is the difference between short-term and long-term containment?
Answer: Short-term stops immediate damage; long-term implements sustainable controls during investigation
Short-term: rapid actions to stop spread. Long-term: sustainable controls allowing continued operations during investigation.
Why is maintaining chain of custody important during incident handling?
Answer: To ensure digital evidence is properly documented, preserved, and admissible in legal proceedings
Chain of custody documents every handler of evidence, ensuring integrity and court admissibility.
What is the purpose of the eradication phase?
Answer: To completely remove the threat and its artifacts from all affected systems
Eradication removes all malware, backdoors, and unauthorized changes, and patches exploited vulnerabilities.
What should a lessons learned meeting focus on after an incident?
Answer: Analyzing what happened, what worked, what could improve, and how to prevent recurrence
Post-incident review evaluates response effectiveness and produces actionable improvements.
What role does a SIEM play in incident detection?
Answer: It collects, correlates, and analyzes log data from multiple sources to identify potential incidents
SIEM aggregates logs from across the network, correlates events using rules, and generates alerts for potential incidents.