CSC Audit, Monitoring & Incident Response 3 — Questions and Answers
Question 1: Under HIPAA, what is the maximum penalty tier for willful neglect of security requirements that is not corrected?
- $1,000 per violation
- $10,000 per violation
- $50,000 per violation
- $1.9 million per violation category per year (Correct answer)
Correct answer: $1.9 million per violation category per year
HIPAA's highest penalty tier for uncorrected willful neglect is $50,000 per violation with an annual cap of $1.9 million per violation category.
Question 2: A security team wants to detect lateral movement within the network. Which monitoring strategy is MOST effective?
- Monitoring only perimeter firewall logs
- Analyzing east-west traffic and internal authentication logs (Correct answer)
- Reviewing public-facing web application logs
- Auditing user password reset activity
Correct answer: Analyzing east-west traffic and internal authentication logs
Lateral movement occurs inside the network, making east-west traffic analysis and internal authentication logs the most relevant detection sources.
Question 3: Which document formally authorizes an IR team to take containment actions during a security incident?
- Business Continuity Plan
- Incident Response Policy (Correct answer)
- System Security Plan
- Risk Register
Correct answer: Incident Response Policy
The Incident Response Policy defines authority, roles, and approved actions, providing formal authorization for the IR team to act during incidents.
Question 4: A compliance audit finds that security logs are not being reviewed daily as required by policy. This is BEST described as:
- A vulnerability
- A threat
- A control deficiency (Correct answer)
- An inherent risk
Correct answer: A control deficiency
A control deficiency exists when an implemented control fails to operate as intended, such as logs existing but not being reviewed as required.
Question 5: Which approach allows an organization to test its incident response plan without disrupting production systems?
- Live fire exercise on production
- Tabletop exercise with key stakeholders (Correct answer)
- Disabling monitoring to simulate blind detection
- Penetration testing without scoping
Correct answer: Tabletop exercise with key stakeholders
Tabletop exercises allow teams to walk through incident scenarios in a discussion-based format, testing the plan without operational risk.
Question 6: What is the primary role of a Security Operations Center (SOC) Tier 1 analyst?
- Conducting forensic investigations of confirmed breaches
- Triage of alerts and initial incident classification (Correct answer)
- Developing new detection rules and threat intelligence
- Managing vulnerability scanning programs
Correct answer: Triage of alerts and initial incident classification
Tier 1 analysts perform alert triage and initial classification, escalating confirmed or complex incidents to higher tiers.
Question 7: Which audit technique involves comparing current system configurations against a known-good baseline?
- Penetration testing
- Configuration compliance scanning (Correct answer)
- Social engineering assessment
- Vulnerability scanning
Correct answer: Configuration compliance scanning
Configuration compliance scanning compares live system settings against approved baselines (e.g., CIS Benchmarks) to identify deviations.
Under HIPAA, what is the maximum penalty tier for willful neglect of security requirements that is not corrected?