Audit, Monitoring & Incident Response Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Audit, Monitoring & Incident Response flashcards as text
An organization experiences a ransomware attack. According to NIST SP 800-61, what is the FIRST phase of the incident response lifecycle that applies?
Answer: Detection and Analysis
Detection and Analysis is the first active phase after Preparation; it involves identifying that an incident has occurred and understanding its scope.
Which log source is MOST useful for detecting unauthorized changes to system files?
Answer: File Integrity Monitoring (FIM) logs
File Integrity Monitoring generates alerts when files are created, modified, or deleted, directly detecting unauthorized changes.
A forensic investigator uses write blockers when imaging drives. What is the purpose of this tool?
Answer: Prevent any data from being written to the evidence drive during acquisition
Write blockers prevent the forensic workstation from accidentally writing to the source evidence drive, preserving its original state.
Under GDPR, within how many hours must a personal data breach be reported to the supervisory authority after becoming aware of it?
Answer: 72 hours
GDPR Article 33 requires organizations to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach.
Which type of audit is performed by the organization itself to assess its own compliance posture?
Answer: Internal audit
Internal audits are conducted by the organization's own staff or internal audit function to assess compliance and control effectiveness.
A SOC detects beaconing traffic at regular 60-second intervals to an external IP. What does this MOST likely indicate?
Answer: Command-and-control (C2) communication from malware
Regular beaconing at fixed intervals to an external IP is a strong indicator of malware communicating with a command-and-control server.
What is the purpose of a chain of custody document in a cybersecurity investigation?
Answer: To record everyone who handled evidence and when
A chain of custody document records the chronological transfer of evidence between individuals to ensure its integrity and admissibility in legal proceedings.