Incident Response and Reporting Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response and Reporting flashcards as text
An organization discovers that an attacker exfiltrated customer credit card data three weeks ago. Under PCI DSS, which entity must be notified immediately?
Answer: The acquiring bank and card brands
PCI DSS requires merchants to notify their acquiring bank (and through them the card brands) immediately upon discovering a cardholder data compromise.
What is the primary goal of the 'eradication' phase in the incident response lifecycle?
Answer: Remove the root cause and all traces of the threat from the environment
Eradication focuses on eliminating the threat actor's foothold, malware, and any backdoors before systems are restored to production.
A security analyst notices unusual outbound traffic at 2 AM. Before escalating, they should first:
Answer: Verify whether the traffic is part of scheduled maintenance or legitimate business activity
Verifying context before escalation prevents false positives and ensures the response effort is proportionate to an actual threat.
Which type of incident response team model uses internal staff who handle incidents as a secondary duty alongside their primary roles?
Answer: Virtual CSIRT
A Virtual CSIRT has no dedicated full-time members; instead, staff from various departments respond to incidents on an on-call basis.
Under NY SHIELD Act, businesses must notify affected New York residents of a breach affecting their private information within:
Answer: As expediently as possible without unreasonable delay
The NY SHIELD Act requires notification in the most expedient time possible and without unreasonable delay, rather than setting a fixed deadline.
In incident response, 'indicators of compromise' (IOCs) are best described as:
Answer: Observable artifacts that suggest a system has been breached
IOCs are forensic evidence such as unusual IP addresses, file hashes, or registry keys that indicate a host or network has been compromised.
Which log source is most useful for detecting unauthorized lateral movement within an enterprise network?
Answer: Windows Security Event Logs (authentication events)
Windows Security Event Logs record authentication events such as failed logins and account usage, making them critical for detecting lateral movement via credential abuse.