CSPM Security Incident Response & Management 1 — Questions and Answers
Question 1: According to NIST SP 800-61, what is the correct order of the incident response lifecycle phases?
- Preparation, Detection & Analysis, Containment/Eradication/Recovery, Post-Incident Activity (Correct answer)
- Detection, Containment, Eradication, Recovery, Lessons Learned
- Identification, Protection, Detection, Response, Recovery
- Triage, Investigation, Containment, Remediation, Closure
Correct answer: Preparation, Detection & Analysis, Containment/Eradication/Recovery, Post-Incident Activity
NIST SP 800-61 defines four phases: Preparation; Detection & Analysis; Containment, Eradication & Recovery; and Post-Incident Activity.
Question 2: What document formally defines the scope, authority, and responsibilities of an incident response team?
- Incident Response Policy
- Security Operations Charter
- Incident Response Plan (Correct answer)
- Risk Register
Correct answer: Incident Response Plan
The Incident Response Plan (IRP) formally defines the team's scope, authority, communication procedures, and step-by-step response procedures.
Question 3: A security project manager discovers a breach mid-project. What should be the FIRST action taken?
- Notify all project stakeholders immediately
- Activate the incident response plan (Correct answer)
- Preserve evidence and isolate affected systems
- Conduct a root cause analysis
Correct answer: Activate the incident response plan
Activating the incident response plan ensures a structured, coordinated approach to handling the breach from the outset.
Question 4: What is the primary purpose of 'containment' during incident response?
- To permanently remove the attacker's tools from the environment
- To restore affected systems to normal operation
- To limit the damage and prevent the incident from spreading (Correct answer)
- To identify the root cause of the incident
Correct answer: To limit the damage and prevent the incident from spreading
Containment's primary goal is to stop further damage by limiting the incident's spread while preserving evidence for analysis.
Question 5: What does 'chain of custody' ensure in a security incident investigation?
- That all affected systems are patched in sequential order
- That evidence is properly collected, documented, and protected from tampering (Correct answer)
- That incident responders follow escalation procedures in order
- That management approves each step before investigators proceed
Correct answer: That evidence is properly collected, documented, and protected from tampering
Chain of custody documents who handled evidence, when, and how, ensuring its integrity and admissibility in legal proceedings.
Question 6: Which incident response team structure consists of security professionals across departments who fulfill IR duties in addition to their normal roles?
- Dedicated Security Incident Response Team (SIRT)
- Managed Security Service Provider (MSSP) Model
- Virtual Incident Response Team (Correct answer)
- Coordinating Incident Response Team
Correct answer: Virtual Incident Response Team
A Virtual Incident Response Team is composed of members with other primary roles who are activated as needed when an incident occurs.
Question 7: What is the primary objective of the 'Post-Incident Activity' phase in NIST's incident response lifecycle?
- To file legal charges against threat actors
- To document lessons learned and improve future response capabilities (Correct answer)
- To restore all affected systems to full operational status
- To notify regulatory bodies of the breach
Correct answer: To document lessons learned and improve future response capabilities
Post-Incident Activity focuses on conducting a lessons-learned review to identify improvements in people, processes, and technology for future incidents.
According to NIST SP 800-61, what is the correct order of the incident response lifecycle phases?