Security Incident Handling Process Flashcards
6 cards from real CCST practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Security Incident Handling Process flashcards as text
What is an Indicator of Compromise (IOC)?
Answer: Observable evidence that a system may have been breached, such as unusual traffic or known malicious IPs
IOCs are artifacts like malicious IPs, file hashes, and suspicious patterns that help identify breaches.
When should law enforcement be notified during a security incident?
Answer: When criminal activity is involved, regulations require it, or law enforcement assistance is needed
Notify when criminal activity occurs, regulations mandate it, or law enforcement capabilities are needed.
What is the purpose of creating a forensic image?
Answer: To create an exact bit-for-bit copy for analysis without modifying original evidence
A forensic image preserves all data including deleted files and slack space, keeping the original untouched.
What is the difference between an incident and an event?
Answer: An event is any observable occurrence; an incident is an event that violates security policy or poses a threat
Events are routine occurrences; incidents are events that indicate security violations or threats.
What is a tabletop exercise and why is it valuable?
Answer: A discussion-based exercise where team members walk through a hypothetical incident to test plans and identify gaps
Tabletop exercises are low-cost simulations that test decision-making and identify weaknesses in the IR plan.
What is the role of an incident response playbook?
Answer: To provide step-by-step procedures for handling specific types of security incidents
Playbooks contain detailed procedures for specific incident types, ensuring consistent and efficient response.