โ† All CSC Flashcard Decks

Audit, Monitoring & Incident Response Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Audit, Monitoring & Incident Response flashcards as text
  1. An organization experiences a ransomware attack. According to NIST SP 800-61, what is the FIRST phase of the incident response lifecycle that applies?

    Answer: Detection and Analysis

    Detection and Analysis is the first active phase after Preparation; it involves identifying that an incident has occurred and understanding its scope.

  2. Which log source is MOST useful for detecting unauthorized changes to system files?

    Answer: File Integrity Monitoring (FIM) logs

    File Integrity Monitoring generates alerts when files are created, modified, or deleted, directly detecting unauthorized changes.

  3. A forensic investigator uses write blockers when imaging drives. What is the purpose of this tool?

    Answer: Prevent any data from being written to the evidence drive during acquisition

    Write blockers prevent the forensic workstation from accidentally writing to the source evidence drive, preserving its original state.

  4. Under GDPR, within how many hours must a personal data breach be reported to the supervisory authority after becoming aware of it?

    Answer: 72 hours

    GDPR Article 33 requires organizations to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach.

  5. Which type of audit is performed by the organization itself to assess its own compliance posture?

    Answer: Internal audit

    Internal audits are conducted by the organization's own staff or internal audit function to assess compliance and control effectiveness.

  6. A SOC detects beaconing traffic at regular 60-second intervals to an external IP. What does this MOST likely indicate?

    Answer: Command-and-control (C2) communication from malware

    Regular beaconing at fixed intervals to an external IP is a strong indicator of malware communicating with a command-and-control server.

  7. What is the purpose of a chain of custody document in a cybersecurity investigation?

    Answer: To record everyone who handled evidence and when

    A chain of custody document records the chronological transfer of evidence between individuals to ensure its integrity and admissibility in legal proceedings.