โ† All CISSP Flashcard Decks

Incident Response and Forensics Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response and Forensics flashcards as text
  1. Which phase of the incident response process involves identifying indicators of compromise and determining the scope of an attack?

    Answer: Detection and Analysis

    Detection and Analysis is the phase where security teams identify indicators of compromise (IoCs), analyze events, and determine the nature and scope of the incident.

  2. In digital forensics, what is the primary purpose of maintaining a chain of custody?

    Answer: To ensure evidence integrity and admissibility in court

    Chain of custody documents every person who handled evidence, ensuring its integrity is preserved and that it remains admissible in legal proceedings.

  3. Which forensic acquisition method produces a bit-for-bit copy of storage media, including deleted files and unallocated space?

    Answer: Physical (raw) acquisition

    Physical (raw) acquisition creates a sector-by-sector, bit-for-bit image of the entire storage device, capturing all data including deleted files and unallocated space.

  4. What is the recommended FIRST action when a security analyst discovers an active intrusion on a production server?

    Answer: Contain the incident to prevent further spread

    Containment is the first priority to limit the damage and prevent the attacker from spreading further, while preserving evidence and minimizing business impact.

  5. Which type of evidence consists of original, unaltered documents or objects that directly prove a fact in an investigation?

    Answer: Best evidence

    Best evidence (also called primary evidence) refers to the original, unaltered document or object; courts prefer it over copies or secondary evidence.

  6. A forensic investigator uses a write blocker during evidence acquisition. What is the primary reason for this?

    Answer: To prevent any writes to the evidence media that would alter it

    A write blocker prevents any data from being written to the original evidence media during acquisition, preserving its integrity and ensuring the copy is forensically sound.

  7. Which NIST Special Publication provides the primary guidelines for computer security incident handling?

    Answer: NIST SP 800-61

    NIST SP 800-61, 'Computer Security Incident Handling Guide,' provides guidelines for establishing and operating an incident response capability.