โ† All CSS Flashcard Decks

Incident Response & Recovery Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response & Recovery flashcards as text
  1. During the containment phase of incident response, which strategy isolates a compromised host while preserving its network traffic data for forensic analysis?

    Answer: Network-based containment using ACLs or VLAN isolation

    Network-based containment via ACLs or VLAN isolation limits the attacker's lateral movement while keeping the host running for forensic evidence capture.

  2. What is the primary purpose of a 'lessons learned' meeting after a security incident?

    Answer: Document what happened and improve future response processes

    The lessons learned meeting captures what worked, what failed, and identifies process improvements to strengthen future incident response.

  3. Which chain-of-custody principle is MOST critical when handling digital evidence collected during an incident?

    Answer: Documenting every person who accessed the evidence

    Chain of custody requires a complete, unbroken record of everyone who accessed the evidence to ensure its integrity and admissibility.

  4. An IR team discovers that an attacker maintained persistence via a scheduled task. Which recovery step should be performed FIRST?

    Answer: Remove the malicious scheduled task

    Removing the persistence mechanism first ensures the attacker cannot regain access before other remediation steps are completed.

  5. What does the term 'dwell time' refer to in the context of incident response?

    Answer: Time between initial compromise and detection

    Dwell time measures how long an attacker remains undetected in the environment, and reducing it is a key metric for IR effectiveness.

  6. Which artifact type would BEST help an analyst determine the timeline of an attacker's lateral movement across Windows systems?

    Answer: Windows Event Log 4624 (logon events)

    Windows Event ID 4624 records successful logons, making it the primary source for reconstructing lateral movement timelines.

  7. When an organization declares a cyber incident a 'major incident,' what typically triggers this escalation?

    Answer: Impact to critical business systems or regulatory thresholds exceeded

    Major incident declarations are triggered by significant business impact, such as outages to critical systems or breaches crossing regulatory notification thresholds.

Incident Response & Recovery Flashcards โ€” CSS Study Cards with Answers