CSL Incident Response & Crisis Management 3 — Questions and Answers
Question 1: After a major incident, a post-mortem reveals the IR plan failed because teams were unfamiliar with their roles. What is the BEST long-term corrective action?
- Replace all IR team members with external consultants
- Implement mandatory recurring IR drills and role-specific training tied to the IR plan (Correct answer)
- Increase the security budget to purchase more detection tools
- Simplify the IR plan to a single-page checklist
Correct answer: Implement mandatory recurring IR drills and role-specific training tied to the IR plan
Regular drills and role-specific training build muscle memory, ensuring team members can execute their responsibilities under pressure during real incidents.
Question 2: During incident containment, an analyst recommends isolating an entire business-critical server. What leadership consideration is MOST important?
- Whether the server's owner will approve the action
- The business impact of isolation versus the risk of continued attacker access (Correct answer)
- The cost of spinning up a replacement server
- Whether the isolation can be performed without logging the action
Correct answer: The business impact of isolation versus the risk of continued attacker access
Leaders must weigh operational disruption against the risk that continued attacker presence causes greater harm, making business impact analysis central to the decision.
Question 3: A threat intelligence feed reports an IOC (Indicator of Compromise) matching traffic in your environment. What is the FIRST step in the IR process?
- Immediately block all outbound traffic matching the IOC
- Validate the IOC against internal logs to confirm whether a real incident exists (Correct answer)
- Notify law enforcement of the potential breach
- Issue a public statement acknowledging a possible security event
Correct answer: Validate the IOC against internal logs to confirm whether a real incident exists
Validating the IOC against internal telemetry confirms whether the indicator represents an active threat or a false positive before taking disruptive action.
Question 4: Under GDPR, within how many hours must a personal data breach be reported to the relevant supervisory authority after the organization becomes aware of it?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 mandates notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.
Question 5: Which type of incident response retainer provides the MOST value for an organization that lacks an internal IR team?
- A break-fix retainer where fees are billed only after an incident occurs
- A proactive retainer that includes pre-engagement scoping, access, and readiness assessments (Correct answer)
- An advisory retainer limited to post-incident reporting
- A training-only retainer that educates staff on phishing awareness
Correct answer: A proactive retainer that includes pre-engagement scoping, access, and readiness assessments
A proactive retainer ensures the IR firm has pre-established access, network knowledge, and tooling deployed before an incident occurs, dramatically reducing response time.
Question 6: During eradication of an advanced persistent threat (APT), why is it critical to remediate ALL identified persistence mechanisms simultaneously?
- To reduce the workload on the remediation team by batching tasks
- Because APTs monitor remediation activity and will re-establish access if any foothold remains (Correct answer)
- To satisfy compliance audit requirements for complete remediation documentation
- Because persistence mechanisms always share the same credentials
Correct answer: Because APTs monitor remediation activity and will re-establish access if any foothold remains
APT actors actively monitor their environment and will leverage surviving persistence mechanisms the moment defenders begin remediation, making simultaneous removal essential.
Question 7: What is the PRIMARY purpose of a 'lessons learned' session conducted after an incident?
- To assign blame and disciplinary action to responsible parties
- To identify process improvements that reduce likelihood and impact of future incidents (Correct answer)
- To satisfy insurance underwriter requirements for incident documentation
- To generate content for public disclosure statements
Correct answer: To identify process improvements that reduce likelihood and impact of future incidents
Lessons learned sessions focus on blameless retrospective analysis to improve detection, response processes, and preventive controls for future incidents.
After a major incident, a post-mortem reveals the IR plan failed because teams were unfamiliar with their roles.
What is the BEST long-term corrective action?