← All CSC Flashcard Decks

Crisis Management & Incident Response Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Crisis Management & Incident Response flashcards as text
  1. Which of the following BEST describes the role of a Security Operations Center (SOC) during a major security incident?

    Answer: Continuous monitoring, triage, and initial response escalation

    A SOC provides 24/7 monitoring and serves as the first point of detection, triage, and escalation during a security incident.

  2. During a crisis, an organization activates its Emergency Operations Center (EOC). What is the PRIMARY function of the EOC?

    Answer: Coordinating cross-functional response activities and decision-making during a crisis

    The EOC serves as a centralized coordination hub for decision-making and resource management across all functions during a crisis or major incident.

  3. What is the concept of 'Indicators of Compromise' (IoCs) used for in incident response?

    Answer: Identifying artifacts that suggest a system has been breached

    IoCs are forensic artifacts—such as unusual IP addresses, file hashes, or registry keys—that indicate a system may have been compromised.

  4. An organization discovers that an attacker has established persistence on their network via a backdoor. After removing the backdoor, what additional step is CRITICAL before declaring recovery complete?

    Answer: Conducting a thorough threat hunt to identify any additional persistence mechanisms

    Threat hunting after removing a known backdoor is critical because attackers often establish multiple persistence mechanisms to maintain access.

  5. Which crisis communication principle states that organizations should be the first to disclose negative news about themselves?

    Answer: Principle of Preemption

    The Principle of Preemption in crisis communications advises organizations to proactively disclose negative news before it is revealed by external parties, preserving credibility.

  6. Which US federal law requires financial institutions to notify their primary federal regulator within 36 hours of a computer-security incident?

    Answer: Computer Security Incident Notification Rule (OCC/FDIC/Fed)

    The Computer Security Incident Notification Rule, jointly issued by the OCC, FDIC, and Federal Reserve, requires bank organizations to notify regulators within 36 hours of a significant security incident.

  7. What is the PRIMARY purpose of a 'hot site' in business continuity planning?

    Answer: A fully operational alternate facility that can be activated immediately after a disaster

    A hot site is a fully equipped alternate facility with hardware, software, and data that mirrors production systems and can be activated immediately following a disaster.