โ† All CSC Flashcard Decks

Audit, Monitoring & Incident Response Flashcards

9 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 9 Audit, Monitoring & Incident Response flashcards as text
  1. What is the purpose of a cybersecurity audit?

    Answer: To assess security controls and compliance

    A cybersecurity audit is a systematic evaluation of an organization's security posture, policies, and controls. Its primary purpose is to assess the effectiveness of security measures, identify vulnerabilities, and ensure compliance with relevant standards and regulations. Audits provide an independent verification of security practices and help improve overall security.

  2. What does security monitoring involve?

    Answer: Observing and analyzing system behavior for threats

    Security monitoring involves continuously observing and analyzing an organization's systems, networks, and data for signs of malicious activity or security threats. This proactive process uses tools like SIEM (Security Information and Event Management) to collect and correlate security events. Its goal is to detect potential incidents early, enabling a rapid response.

  3. What is an incident response plan?

    Answer: A strategy to address cybersecurity threats and breaches

    An incident response plan is a predefined, documented strategy that outlines the steps an organization will take to prepare for, detect, contain, eradicate, recover from, and learn from cybersecurity incidents or breaches. It provides a structured approach to minimize damage, restore normal operations, and ensure business continuity. This plan is crucial for effective crisis management.

  4. What is log analysis used for in monitoring?

    Answer: To detect and understand security incidents

    Log analysis is a fundamental component of security monitoring, involving the systematic review of system, application, and network logs. By analyzing these logs, security professionals can identify unusual patterns, suspicious activities, and indicators of compromise. This process is critical for detecting security incidents, understanding their scope, and aiding in forensic investigations.

  5. Which team is primarily responsible for incident handling?

    Answer: CSIRT

    The CSIRT (Computer Security Incident Response Team) is the specialized team primarily responsible for handling cybersecurity incidents within an organization. This team's functions include detecting, analyzing, containing, eradicating, and recovering from security breaches. Their expertise is crucial for minimizing the impact of incidents and restoring normal operations.

  6. What is the first phase in the incident response process?

    Answer: Preparation

    The first phase in the incident response process is Preparation. This phase involves establishing policies, procedures, tools, and training necessary to effectively handle incidents before they occur. Proper preparation ensures that an organization is ready to respond swiftly and efficiently when a security incident inevitably happens, minimizing its potential impact.

  7. Why is post-incident review important?

    Answer: To learn from the incident and enhance procedures

    Post-incident review is a critical phase in incident response. It involves analyzing what happened, how the incident was handled, and identifying areas for improvement in security policies, procedures, and technologies. This process ensures that an organization continuously strengthens its defenses and response capabilities, preventing similar incidents or mitigating their impact in the future.

  8. What is the goal of containment during an incident?

    Answer: To restrict the impact of the incident

    Containment is a crucial step in the incident response lifecycle. Its primary goal is to limit the scope and impact of a security incident, preventing it from spreading further within the network or causing more damage. This might involve isolating affected systems, disconnecting networks, or implementing temporary fixes to stop the attack's progression.

  9. Which tool is commonly used in monitoring and alerting?

    Answer: SIEM (Security Information and Event Management)

    SIEM (Security Information and Event Management) systems are essential tools for cybersecurity monitoring and alerting. They collect and aggregate log data from various sources across an organization's IT infrastructure, such as servers, network devices, and applications. By analyzing this data in real-time, SIEMs can detect suspicious activities, identify potential threats, and generate alerts for security teams to investigate.