โ† All CSC Flashcard Decks

Incident Response and Reporting Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response and Reporting flashcards as text
  1. A ransomware attack has encrypted production servers. The FIRST priority of the incident response team should be:

    Answer: Preserve forensic evidence then contain the spread

    Preserving evidence while containing the attack prevents further damage and maintains the ability to investigate and comply with reporting obligations.

  2. Which framework specifically provides a taxonomy of adversary tactics and techniques useful for mapping the stages of a cybersecurity incident?

    Answer: MITRE ATT&CK

    MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used to model attacker behavior.

  3. An organization subject to FISMA experiences a significant cybersecurity incident. Which agency must be notified?

    Answer: US-CERT (CISA)

    FISMA requires federal agencies and their contractors to report cybersecurity incidents to US-CERT (now part of CISA) within defined timeframes.

  4. What distinguishes a 'security event' from a 'security incident' in incident classification?

    Answer: An event is any observable occurrence; an incident is an event that adversely affects the organization

    A security event is any observable occurrence in a system, while a security incident is an event (or series of events) that negatively impacts confidentiality, integrity, or availability.

  5. During incident response, 'out-of-band' communication channels are used primarily to:

    Answer: Communicate securely when primary systems may be compromised

    Out-of-band channels (e.g., personal phones, secondary email) ensure responders can coordinate securely if the organization's primary communication systems are compromised.

  6. Which element is LEAST likely to appear in a well-structured incident response report submitted to executive leadership?

    Answer: Full packet capture hex dumps

    Raw packet capture hex dumps are highly technical artifacts appropriate for forensic analysts, not for executive leadership reports focused on business impact and decisions.

  7. An employee inadvertently emails a spreadsheet containing 500 customer SSNs to the wrong recipient. This is classified as:

    Answer: A data breach requiring notification assessment

    Accidental disclosure of personal information such as SSNs to unauthorized parties typically qualifies as a data breach requiring assessment under applicable breach notification laws.