Incident Response and Forensics Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Incident Response and Forensics flashcards as text
During a forensic investigation, an investigator calculates an MD5 hash of a disk image immediately after acquisition. What is this process called?
Answer: Hash validation / integrity verification
Hashing the evidence immediately after acquisition and then verifying the hash before analysis is called integrity verification, confirming the image has not been altered.
Which concept describes the systematic process of identifying, preserving, analyzing, and presenting digital evidence in a legally acceptable manner?
Answer: Digital forensics
Digital forensics is the scientific discipline of identifying, preserving, analyzing, and presenting digital evidence in ways that are legally defensible.
An organization's IR plan calls for isolating an infected workstation by disabling its network interface. Which containment strategy does this represent?
Answer: Short-term containment
Short-term containment involves immediate actions like disabling a network interface to stop the spread of an incident while longer-term solutions are prepared.
What is 'locard's exchange principle' and how does it apply to digital forensics?
Answer: Every contact leaves a trace — digital actions leave artifacts behind
Locard's Exchange Principle states that every contact leaves a trace; in digital forensics, this means that whenever someone interacts with a system, artifacts such as logs and registry entries are left behind.
Which of the following is a primary benefit of having a Computer Security Incident Response Team (CSIRT)?
Answer: Providing a structured, coordinated response to security incidents
A CSIRT provides an organized, expert team that can respond quickly and effectively to incidents, minimizing damage and recovery time through coordinated effort.
In the context of incident response, what does the term 'dwell time' refer to?
Answer: The length of time an attacker remains undetected in a network
Dwell time (also called mean time to detect) is the period an attacker is present and active in a network before being discovered, which attackers try to maximize.
Which type of malware analysis involves executing a suspicious file in a controlled environment to observe its behavior?
Answer: Dynamic analysis
Dynamic analysis (behavioral analysis) involves running the malware in a controlled sandbox environment to observe its actual behavior, network connections, and system changes.