← All CSS Flashcard Decks

Incident Response & Recovery Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Incident Response & Recovery flashcards as text
  1. Which type of malware is MOST associated with requiring an organization to activate its backup recovery procedures due to data unavailability?

    Answer: Ransomware

    Ransomware encrypts victim data and demands payment, frequently forcing organizations to restore from backups as their primary recovery method.

  2. During incident recovery, what is 'reconstitution' and when does it occur?

    Answer: Reconstitution is restoring systems to full operational status; it occurs after eradication is confirmed

    Reconstitution involves rebuilding and restoring affected systems to normal operations and is performed only after all threats have been confirmed as removed.

  3. Which type of indicator would be found in a threat intelligence report and used to detect malicious activity at the network perimeter?

    Answer: Indicator of Compromise (IoC) such as malicious IP addresses or domains

    Indicators of Compromise (IoCs) like known malicious IPs, domains, and file hashes are shared in threat intelligence and used to configure perimeter detection rules.

  4. What is the purpose of a 'forensic hold' or litigation hold during an incident investigation?

    Answer: Preserving all potentially relevant evidence to prevent destruction or modification

    A forensic or litigation hold legally mandates that all relevant data be preserved intact to support potential legal proceedings following an incident.

  5. An analyst finds that an attacker used 'living off the land' (LotL) techniques during an intrusion. What does this mean for recovery validation?

    Answer: Standard antivirus scans may miss the compromise since built-in tools were abused

    LotL techniques abuse legitimate system tools like PowerShell and WMI, so signature-based antivirus may not detect malicious activity during recovery validation.

  6. What should an IR team do IMMEDIATELY upon confirming that personal data was exfiltrated in a breach, under typical US state breach notification laws?

    Answer: Assess notification obligations and initiate required disclosure timelines

    US state breach notification laws require organizations to assess their disclosure obligations and begin notifying affected parties within defined timeframes, often 30–60 days.

  7. Which concept describes the minimum acceptable backup age that an organization can tolerate losing in a recovery scenario?

    Answer: Recovery Point Objective (RPO)

    RPO defines the maximum tolerable data loss measured in time, dictating how frequently backups must be created to meet business requirements.