← All CSC Flashcard Decks

Crisis Management & Incident Response Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Crisis Management & Incident Response flashcards as text
  1. During a ransomware attack, which action should be taken FIRST after isolating affected systems?

    Answer: Notify law enforcement and preserve forensic evidence

    Law enforcement notification and evidence preservation are critical first steps before remediation to support investigation and potential prosecution.

  2. What is the primary purpose of a tabletop exercise in incident response planning?

    Answer: To walk stakeholders through response procedures in a discussion-based format

    Tabletop exercises are discussion-based simulations where participants walk through response procedures without affecting live systems.

  3. Which document formally authorizes an incident response team to take action during a security event?

    Answer: Rules of Engagement (ROE)

    Rules of Engagement define the scope and authority granted to the incident response team during a security event.

  4. A company experiences a data breach affecting 50,000 customer records. Under most US state breach notification laws, what is the typical maximum notification window?

    Answer: 30–90 days

    Most US state breach notification laws require notifying affected individuals within 30 to 90 days of breach discovery.

  5. What is the BEST definition of 'dwell time' in the context of incident response?

    Answer: Time between initial compromise and detection of the breach

    Dwell time measures how long an attacker remains undetected in a network between initial compromise and discovery.

  6. Which phase of the NIST incident response lifecycle focuses on learning from past incidents to improve future response?

    Answer: Post-Incident Activity

    The Post-Incident Activity phase includes lessons-learned reviews to improve processes and prevent recurrence.

  7. During incident response, a 'chain of custody' document is maintained primarily to:

    Answer: Ensure evidence admissibility in legal or regulatory proceedings

    Chain of custody documents the handling of evidence to ensure its integrity and admissibility in court or regulatory hearings.