← All CCSK Flashcard Decks

Incident Response and Business Continuity in Cloud Flashcards

6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Incident Response and Business Continuity in Cloud flashcards as text
  1. What does CCSK identify as a key requirement for cloud security incident notification to affected parties?

    Answer: Organizations must understand contractual and regulatory breach notification obligations and meet defined timelines

    Breach notification requirements vary by regulation (GDPR, HIPAA, state laws) and contracts, requiring organizations to know their obligations and meet mandatory timelines.

  2. What is 'post-incident review' (PIR) and what value does it provide after a cloud security incident?

    Answer: A structured analysis of what happened, why, and how to prevent recurrence — improving future detection and response

    PIR (also called a post-mortem or lessons-learned review) systematically analyzes incident causes and response gaps to drive improvements in controls and procedures.

  3. According to CCSK, how does 'auto-scaling' in cloud environments complicate incident response?

    Answer: New instances spin up and old ones terminate automatically, potentially destroying forensic evidence and confusing attack timelines

    Auto-scaling terminates instances based on load, destroying forensic artifacts; investigators must ensure logging is centralized before instances disappear.

  4. What is a 'tabletop exercise' in the context of CCSK cloud incident response preparedness?

    Answer: A discussion-based simulation where stakeholders walk through an incident scenario to identify gaps in plans and roles

    Tabletop exercises simulate incident scenarios in a discussion format, revealing gaps in IR plans, roles, and communication without requiring actual system changes.

  5. What does CCSK recommend regarding cloud provider support and coordination during a security incident?

    Answer: Establish provider escalation contacts and incident notification procedures in advance, before an incident occurs

    Pre-establishing escalation contacts and notification procedures with providers ensures faster response and access to provider-side evidence when an incident occurs.

  6. According to CCSK, what is the security benefit of 'immutable infrastructure' for incident response?

    Answer: Compromised instances can be terminated and replaced from a known-good baseline, simplifying recovery

    With immutable infrastructure, recovery means destroying the compromised instance and redeploying from the golden image, eliminating the need to 'clean' infected systems.