Audit, Monitoring & Incident Response Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Audit, Monitoring & Incident Response flashcards as text
Which concept describes the practice of proactively searching through networks and datasets to find threats that evade existing security controls?
Answer: Threat hunting
Threat hunting is a proactive approach where analysts search for indicators of compromise and hidden threats that automated tools have not detected.
An organization wants to ensure audit trails cannot be tampered with by system administrators. Which control BEST achieves this?
Answer: Forwarding logs to a remote, isolated SIEM where admins lack write access
Forwarding logs to a separate system where local admins cannot modify them ensures log integrity even if the source system is compromised.
Which NIST CSF function is MOST associated with activities like log review, SIEM alerting, and anomaly detection?
Answer: Detect
The Detect function encompasses continuous monitoring activities that identify cybersecurity events in a timely manner.
A compliance officer reviews an audit report showing a 'significant deficiency.' How does this differ from a 'material weakness'?
Answer: A material weakness indicates a higher likelihood that a material misstatement will not be prevented or detected
A material weakness represents a more severe control failure with a reasonable possibility that a material misstatement will go undetected, while a significant deficiency is less severe but still important.
During incident containment, an analyst isolates an infected workstation. What is the NEXT logical step?
Answer: Collect forensic evidence before eradication
After containment, forensic evidence must be collected to understand the attack before eradication removes artifacts needed for investigation.
Which indicator would BEST help an analyst determine if a security alert represents a true positive?
Answer: Corroboration of the alert with supporting evidence from multiple log sources
Correlating an alert with supporting evidence from multiple independent log sources significantly increases confidence that it represents a real threat.
A company's IR plan has not been tested or updated in three years. Which risk does this MOST directly create?
Answer: The plan may be misaligned with the current environment, personnel, and threats
An untested, outdated IR plan may reference obsolete systems, departed staff, or outdated threats, rendering it ineffective during an actual incident.