CND Incident Response & Disaster Recovery 5 — Questions and Answers
Question 1: Under the NIST Cybersecurity Framework, which function covers activities to restore services impaired by a cybersecurity incident?
- Identify
- Protect
- Respond
- Recover (Correct answer)
Correct answer: Recover
The 'Recover' function encompasses activities to restore capabilities or services that were impaired during an incident, including communications and improvement plans.
Question 2: What is 'data exfiltration' in the context of a security incident?
- Unauthorized copying or transfer of data from an organization to an external destination (Correct answer)
- Encrypting sensitive data before it is backed up
- The process of deleting logs to cover attacker tracks
- Moving data between internal network segments
Correct answer: Unauthorized copying or transfer of data from an organization to an external destination
Data exfiltration refers to the unauthorized transfer of data from within an organization to an outside location controlled by an attacker.
Question 3: Which document provides pre-approved procedures for responding to common incident types, reducing decision fatigue during an active incident?
- Risk assessment report
- Playbook (runbook) (Correct answer)
- Business impact analysis
- Security awareness policy
Correct answer: Playbook (runbook)
Playbooks are pre-defined, step-by-step response procedures for specific incident scenarios that allow responders to act quickly and consistently without improvising under pressure.
Question 4: In forensic investigations, what is 'write blocking' and why is it used?
- Blocking network write operations to prevent lateral movement
- Using a hardware or software device to prevent any changes to the original evidence media (Correct answer)
- Disabling write permissions on the SIEM to protect log integrity
- Encrypting evidence before transport to the forensic lab
Correct answer: Using a hardware or software device to prevent any changes to the original evidence media
A write blocker prevents any write operations to the original storage media during imaging, ensuring that the evidence remains unaltered and legally admissible.
Question 5: Which business continuity concept identifies which business processes are most critical and must be restored first after a disaster?
- Risk Register
- Business Impact Analysis (BIA) (Correct answer)
- Vulnerability Assessment
- Gap Analysis
Correct answer: Business Impact Analysis (BIA)
A Business Impact Analysis (BIA) identifies critical business functions, quantifies the impact of disruptions, and prioritizes recovery order based on operational and financial consequences.
Question 6: During the recovery phase of incident response, which action verifies that eradication was successful before returning systems to production?
- Running a full antivirus scan only
- Reinstalling the OS and verifying system integrity against a known-good baseline (Correct answer)
- Changing all user passwords
- Updating firewall rules to block the attacker's IP
Correct answer: Reinstalling the OS and verifying system integrity against a known-good baseline
Rebuilding from a known-good baseline and verifying integrity ensures no persistent backdoors or malware remnants remain before the system rejoins production.
Question 7: An organization wants to test whether employees can recognize phishing emails as part of their IR preparedness program. Which activity best accomplishes this?
- Deploying a new email filtering gateway
- Conducting a simulated phishing campaign (Correct answer)
- Reviewing email logs for the past 30 days
- Installing endpoint detection and response (EDR) software
Correct answer: Conducting a simulated phishing campaign
Simulated phishing campaigns send controlled fake phishing emails to employees and measure click rates, providing data to improve security awareness training.
Under the NIST Cybersecurity Framework, which function covers activities to restore services impaired by a cybersecurity incident?