CSPM Security Incident Response & Management 2 — Questions and Answers
Question 1: What is the distinction between a security 'event' and a security 'incident'?
- Events are external threats while incidents are internal threats
- An event is any observable occurrence; an incident is an event that negatively impacts security (Correct answer)
- Events are logged automatically while incidents require manual detection
- An incident is a potential threat while an event is a confirmed breach
Correct answer: An event is any observable occurrence; an incident is an event that negatively impacts security
A security event is any observable system occurrence, while an incident is specifically an event that threatens or violates security policies, AUPs, or standard security practices.
Question 2: During which incident response phase is forensic evidence collected and analyzed?
- Preparation
- Containment
- Detection & Analysis (Correct answer)
- Post-Incident Activity
Correct answer: Detection & Analysis
The Detection & Analysis phase involves collecting, preserving, and analyzing evidence to understand the nature, scope, and impact of the incident.
Question 3: What is the purpose of an Incident Response Retainer with an external security firm?
- To outsource all security operations to a third party permanently
- To ensure pre-negotiated access to specialized IR expertise when an incident occurs (Correct answer)
- To comply with regulatory requirements for third-party security audits
- To provide 24/7 monitoring of the organization's network
Correct answer: To ensure pre-negotiated access to specialized IR expertise when an incident occurs
An IR retainer pre-negotiates terms, pricing, and access with a specialized firm so organizations can quickly engage expert help during a major incident without delays.
Question 4: During the eradication phase of incident response, what is the primary goal?
- Preventing the incident from affecting additional systems
- Restoring systems to their pre-incident state
- Removing all traces of the threat from the environment (Correct answer)
- Notifying affected customers and stakeholders
Correct answer: Removing all traces of the threat from the environment
Eradication focuses on completely removing the threat — including malware, backdoors, and unauthorized accounts — from all affected systems.
Question 5: Which metric measures the average time between when an incident is detected and when it is fully contained?
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Mean Time to Contain (MTTC) (Correct answer)
- Recovery Time Objective (RTO)
Correct answer: Mean Time to Contain (MTTC)
Mean Time to Contain (MTTC) specifically measures the time elapsed from detection to successful containment of the threat.
Question 6: What is a tabletop exercise in the context of incident response?
- A physical simulation where responders practice isolating infected machines
- A discussion-based exercise where participants walk through a hypothetical incident scenario (Correct answer)
- An automated red team attack on production systems
- A post-incident review meeting focused on metrics and KPIs
Correct answer: A discussion-based exercise where participants walk through a hypothetical incident scenario
A tabletop exercise is a low-cost, discussion-based drill where key stakeholders verbally walk through an incident scenario to identify gaps in the response plan without affecting real systems.
Question 7: Which role is typically responsible for declaring a security incident and initiating the formal response process in a large organization?
- Network Administrator
- Security Analyst
- Incident Response Manager or CISO (Correct answer)
- Help Desk Technician
Correct answer: Incident Response Manager or CISO
The Incident Response Manager or CISO typically holds the authority to formally declare an incident and activate the full IR plan, ensuring appropriate resources are mobilized.
What is the distinction between a security 'event' and a security 'incident'?