โ† All CSC Flashcard Decks

Audit, Monitoring & Incident Response Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Audit, Monitoring & Incident Response flashcards as text
  1. Under HIPAA, what is the maximum penalty tier for willful neglect of security requirements that is not corrected?

    Answer: $1.9 million per violation category per year

    HIPAA's highest penalty tier for uncorrected willful neglect is $50,000 per violation with an annual cap of $1.9 million per violation category.

  2. A security team wants to detect lateral movement within the network. Which monitoring strategy is MOST effective?

    Answer: Analyzing east-west traffic and internal authentication logs

    Lateral movement occurs inside the network, making east-west traffic analysis and internal authentication logs the most relevant detection sources.

  3. Which document formally authorizes an IR team to take containment actions during a security incident?

    Answer: Incident Response Policy

    The Incident Response Policy defines authority, roles, and approved actions, providing formal authorization for the IR team to act during incidents.

  4. A compliance audit finds that security logs are not being reviewed daily as required by policy. This is BEST described as:

    Answer: A control deficiency

    A control deficiency exists when an implemented control fails to operate as intended, such as logs existing but not being reviewed as required.

  5. Which approach allows an organization to test its incident response plan without disrupting production systems?

    Answer: Tabletop exercise with key stakeholders

    Tabletop exercises allow teams to walk through incident scenarios in a discussion-based format, testing the plan without operational risk.

  6. What is the primary role of a Security Operations Center (SOC) Tier 1 analyst?

    Answer: Triage of alerts and initial incident classification

    Tier 1 analysts perform alert triage and initial classification, escalating confirmed or complex incidents to higher tiers.

  7. Which audit technique involves comparing current system configurations against a known-good baseline?

    Answer: Configuration compliance scanning

    Configuration compliance scanning compares live system settings against approved baselines (e.g., CIS Benchmarks) to identify deviations.