โ† All CSS Flashcard Decks

Incident Response & Recovery Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response & Recovery flashcards as text
  1. When performing root cause analysis (RCA) after an incident, which framework helps identify contributing factors across people, processes, and technology?

    Answer: The 5 Whys or Fishbone (Ishikawa) diagram

    The 5 Whys and Fishbone diagrams are root cause analysis tools that systematically trace failures across human, process, and technical contributing factors.

  2. An attacker compromised a build server and inserted malicious code into a software release. Which type of incident does this represent?

    Answer: Supply chain attack

    Compromising a build server to inject malicious code into software releases is a textbook supply chain attack targeting downstream users.

  3. During the detection phase, a SIEM generates thousands of alerts but only a small number represent real threats. What challenge does this describe?

    Answer: Alert fatigue due to high false positive rates

    Alert fatigue occurs when security teams are overwhelmed by high volumes of false positive alerts, increasing the risk of missing genuine threats.

  4. What is the role of a 'scribe' during a major incident response operation?

    Answer: Documenting actions taken, decisions made, and timeline of events in real time

    The scribe maintains a real-time log of all IR activities, decisions, and timestamps to support post-incident review and potential legal requirements.

  5. Which approach to system recovery provides the STRONGEST assurance that malware has been fully removed from a compromised endpoint?

    Answer: Wiping and reimaging the system from a known-good baseline image

    Wiping and reimaging from a trusted baseline eliminates all malware and attacker modifications, providing the highest confidence of full remediation.

  6. An IR team is responding to a breach where the attacker exfiltrated data over HTTPS to an external server. Which log source would BEST help confirm this exfiltration?

    Answer: Firewall or proxy logs showing large outbound HTTPS transfers to unknown IPs

    Firewall and proxy logs capture outbound connection details including destination IPs, data volumes, and protocols, making them ideal for detecting HTTPS-based exfiltration.

  7. After a ransomware incident, an organization restores from backup but does not address the initial access vector. What risk does this create?

    Answer: The attacker can reinfect the organization using the same vulnerability

    Restoring without closing the initial access vector leaves the organization vulnerable to the same attack method, resulting in re-infection.