CSC Crisis Management & Incident Response 2 — Questions and Answers
Question 1: During a ransomware attack, which action should be taken FIRST after isolating affected systems?
- Pay the ransom to restore operations quickly
- Notify law enforcement and preserve forensic evidence (Correct answer)
- Reimage all affected machines immediately
- Restore from backup without investigation
Correct answer: Notify law enforcement and preserve forensic evidence
Law enforcement notification and evidence preservation are critical first steps before remediation to support investigation and potential prosecution.
Question 2: What is the primary purpose of a tabletop exercise in incident response planning?
- To test the technical capabilities of security tools
- To simulate a real attack on production systems
- To walk stakeholders through response procedures in a discussion-based format (Correct answer)
- To measure network detection response times
Correct answer: To walk stakeholders through response procedures in a discussion-based format
Tabletop exercises are discussion-based simulations where participants walk through response procedures without affecting live systems.
Question 3: Which document formally authorizes an incident response team to take action during a security event?
- Business Impact Analysis (BIA)
- Rules of Engagement (ROE) (Correct answer)
- Memorandum of Understanding (MOU)
- Service Level Agreement (SLA)
Correct answer: Rules of Engagement (ROE)
Rules of Engagement define the scope and authority granted to the incident response team during a security event.
Question 4: A company experiences a data breach affecting 50,000 customer records. Under most US state breach notification laws, what is the typical maximum notification window?
- 24 hours
- 30–90 days (Correct answer)
- 6 months
- 1 year
Correct answer: 30–90 days
Most US state breach notification laws require notifying affected individuals within 30 to 90 days of breach discovery.
Question 5: What is the BEST definition of 'dwell time' in the context of incident response?
- Time taken to fully restore systems after an incident
- Time between initial compromise and detection of the breach (Correct answer)
- Duration of a denial-of-service attack
- Time required to complete a forensic investigation
Correct answer: Time between initial compromise and detection of the breach
Dwell time measures how long an attacker remains undetected in a network between initial compromise and discovery.
Question 6: Which phase of the NIST incident response lifecycle focuses on learning from past incidents to improve future response?
- Preparation
- Detection and Analysis
- Containment, Eradication, and Recovery
- Post-Incident Activity (Correct answer)
Correct answer: Post-Incident Activity
The Post-Incident Activity phase includes lessons-learned reviews to improve processes and prevent recurrence.
Question 7: During incident response, a 'chain of custody' document is maintained primarily to:
- Speed up the remediation process
- Ensure evidence admissibility in legal or regulatory proceedings (Correct answer)
- Track responder working hours
- Document system uptime metrics
Correct answer: Ensure evidence admissibility in legal or regulatory proceedings
Chain of custody documents the handling of evidence to ensure its integrity and admissibility in court or regulatory hearings.
During a ransomware attack, which action should be taken FIRST after isolating affected systems?