CSX Use of Force Policies & Procedures 3 — Questions and Answers
Question 1: In a cyber use-of-force policy, the 'distinction' principle requires that offensive or active-defense actions:
- Are kept secret from all non-security staff
- Discriminate between legitimate military/attacker targets and civilian/innocent systems (Correct answer)
- Use only tools developed internally by the organization
- Are completed within a defined time window
Correct answer: Discriminate between legitimate military/attacker targets and civilian/innocent systems
Distinction, borrowed from the law of armed conflict, requires that cyber operations target only adversary systems and avoid collateral damage to civilian or neutral infrastructure.
Question 2: An organization's policy classifies cyber responses into 'Tier 1: passive monitoring,' 'Tier 2: active defense,' and 'Tier 3: offensive countermeasures.' Who should authorize Tier 3 actions?
- SOC manager
- CISO alone
- Executive leadership with legal counsel review (Correct answer)
- Threat intelligence director
Correct answer: Executive leadership with legal counsel review
Tier 3 offensive countermeasures carry the highest legal risk and potential for escalation, requiring executive-level sign-off and legal review before execution.
Question 3: A penetration tester has found that an attacker's exfiltration server contains stolen data. The security team wants to delete the data remotely. This action is best characterized as:
- Permitted active defense because the data belongs to them
- An unauthorized offensive cyber operation regardless of data ownership (Correct answer)
- Acceptable under the CFAA good-samaritan exception
- Legal because it prevents further harm
Correct answer: An unauthorized offensive cyber operation regardless of data ownership
Accessing and modifying a third-party system without authorization is prohibited under the CFAA even when the goal is to recover stolen property; no private good-samaritan exception exists.
Question 4: Which documentation requirement is MOST critical immediately after an organization executes an active cyber defense measure?
- Publishing a press release
- Creating a detailed chain-of-custody and action log (Correct answer)
- Notifying the attacker's ISP
- Filing a patent on the defensive technique
Correct answer: Creating a detailed chain-of-custody and action log
A detailed action log and chain-of-custody record supports legal defensibility, incident review, and regulatory compliance following any active defensive measure.
Question 5: Under the concept of 'due diligence' in cyber use-of-force policy, a state or organization is obligated to:
- Respond to every cyber incident with an equivalent countermeasure
- Prevent its infrastructure from being used as a launchpad for attacks against others (Correct answer)
- Share all threat intelligence with international partners
- Disclose every cyber incident to the public within 72 hours
Correct answer: Prevent its infrastructure from being used as a launchpad for attacks against others
Due diligence obligates entities to ensure their systems and infrastructure are not knowingly used to harm others, including preventing their networks from serving as attack intermediaries.
Question 6: A security policy states that 'sinkholing' a malicious domain is an approved active-defense measure. What makes sinkholing generally permissible where hack-back is not?
- Sinkholing requires no technical expertise
- Sinkholing redirects traffic to a controlled server rather than accessing attacker-owned systems (Correct answer)
- Sinkholing is always authorized by the CFAA
- Sinkholing destroys the attacker's infrastructure
Correct answer: Sinkholing redirects traffic to a controlled server rather than accessing attacker-owned systems
Sinkholing redirects DNS traffic to a defender-controlled IP without accessing or modifying systems the attacker owns, keeping the action within the defender's authorized network perimeter.
Question 7: An organization's cyber use-of-force policy requires 'attribution confidence' before escalating a response. What is the MAIN reason attribution is required before escalation?
- To satisfy marketing requirements for press releases
- To avoid taking harmful action against the wrong party and triggering unintended escalation (Correct answer)
- To ensure the SOC receives credit for the response
- To comply with GDPR notification timelines
Correct answer: To avoid taking harmful action against the wrong party and triggering unintended escalation
Poor attribution can result in retaliatory or defensive actions directed at innocent third parties, escalating conflicts and creating legal and diplomatic consequences.
In a cyber use-of-force policy, the 'distinction' principle requires that offensive or active-defense actions: