Incident Response & Recovery Flashcards
7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response & Recovery flashcards as text
Which NIST SP 800-61 phase focuses on minimizing damage and preventing further unauthorized access?
Answer: Containment, Eradication, and Recovery
The Containment, Eradication, and Recovery phase directly addresses stopping the attack, removing threats, and restoring affected systems.
An IR analyst needs to capture volatile memory from a live compromised system. Which tool is BEST suited for this task?
Answer: Winpmem or DumpIt for memory acquisition
Winpmem and DumpIt are purpose-built for acquiring physical memory from live Windows systems without disrupting running processes.
What is the difference between an Incident Response Plan (IRP) and a Business Continuity Plan (BCP)?
Answer: IRP addresses security event response; BCP ensures critical business functions continue during disruptions
An IRP governs how to respond to and recover from security incidents, while a BCP ensures essential business operations continue under any disruptive condition.
During eradication, a team removes malware but fails to identify all persistence mechanisms. Which outcome is MOST likely?
Answer: Reinfection occurs as the attacker re-establishes access via remaining backdoors
Incomplete eradication leaves surviving persistence mechanisms that allow the attacker to regain access, effectively restarting the incident.
Which metric is used to measure the effectiveness of an incident response team's detection capabilities?
Answer: Mean Time to Detect (MTTD)
MTTD measures the average time from when an incident occurs to when it is detected, directly reflecting detection capability effectiveness.
An organization wants to test its incident response plan with minimal disruption to operations. Which exercise type is MOST appropriate?
Answer: Tabletop exercise using discussion-based scenarios
Tabletop exercises allow teams to walk through incident scenarios verbally without impacting production systems, making them ideal for low-disruption testing.
What is the significance of establishing a 'war room' or dedicated command center during a major security incident?
Answer: It centralizes communication and decision-making among response team members
A war room or command center brings key stakeholders together to enable rapid, coordinated decision-making and clear communication throughout the incident.