Incident Response and Reporting Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Incident Response and Reporting flashcards as text
Under the NIST Computer Security Incident Handling Guide (SP 800-61), which phase comes immediately after 'Detection and Analysis'?
Answer: Containment, Eradication, and Recovery
NIST SP 800-61 defines the incident response lifecycle as: Preparation → Detection and Analysis → Containment, Eradication, and Recovery → Post-Incident Activity.
A CFE is examining a phishing incident. The examiner discovers that an employee forwarded a suspicious email to their personal account before reporting it. This action MOST directly concerns which forensic issue?
Answer: Spoliation of evidence and potential contamination of the investigation scope
Forwarding the email to a personal account constitutes potential spoliation by moving evidence outside the controlled environment and expanding the scope of compromise.
When responding to a ransomware incident, which action should be taken FIRST after confirming the infection?
Answer: Isolate affected systems from the network to prevent further spread
Network isolation is the immediate containment priority to prevent ransomware from spreading laterally to additional systems and causing greater damage.
In incident reporting, the term 'Indicators of Compromise' (IOCs) refers to:
Answer: Artifacts and evidence that suggest a system or network has been breached
IOCs are forensic artifacts such as unusual IP addresses, malicious file hashes, or suspicious registry keys that indicate a system has been compromised.
A forensic examiner must testify about incident findings in court. Which documentation practice BEST supports the credibility of testimony?
Answer: Maintaining contemporaneous, detailed notes and logs created at the time of examination
Contemporaneous notes created during the examination are more credible than reconstructed records and are better able to withstand cross-examination challenges.
Which of the following is the BEST example of a 'short-term containment' strategy during an active incident?
Answer: Blocking the attacker's IP address at the firewall while preserving the compromised system for analysis
Short-term containment focuses on immediate actions like blocking malicious traffic while leaving evidence intact for forensic examination, unlike long-term remediation steps.
A CFE discovers that an attacker used legitimate administrative tools (living-off-the-land techniques) during an intrusion. Why does this complicate the investigation?
Answer: Malicious activity blends with normal administrative behavior, making detection and attribution harder
Living-off-the-land techniques exploit trusted tools like PowerShell or WMI, making malicious activity harder to distinguish from routine administrative tasks in logs.