Incident Response Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response flashcards as text
During an incident investigation, an analyst finds evidence that data was exfiltrated via DNS queries. Which technique was likely used?
Answer: DNS tunneling
DNS tunneling encodes data within DNS query and response packets to covertly exfiltrate information through DNS protocol.
Which chain-of-custody practice is MOST important when collecting digital evidence from a live system?
Answer: Document every action taken and hash all collected artifacts
Documenting all actions and hashing artifacts ensures evidence integrity and maintains a defensible chain of custody for legal proceedings.
A SOC analyst identifies a process injecting code into a legitimate Windows process (e.g., svchost.exe). Which MITRE ATT&CK technique does this represent?
Answer: Process injection
Process injection is a MITRE ATT&CK technique where adversaries inject malicious code into legitimate running processes to evade detection.
Which log source would be MOST useful for identifying lateral movement via Pass-the-Hash attacks within a Windows environment?
Answer: Windows Security Event Log (Event ID 4624)
Windows Security Event ID 4624 (logon events) with Logon Type 3 and NTLM authentication can indicate Pass-the-Hash lateral movement.
An analyst is performing triage on 50 simultaneous alerts. Which approach BEST prioritizes response efforts?
Answer: Prioritize by asset criticality and potential business impact
Triaging by asset criticality and business impact ensures the most damaging potential incidents receive immediate attention.
During post-incident analysis, the team discovers the attacker maintained persistence for 90 days before detection. Which term describes this period?
Answer: Dwell time
Dwell time refers to the duration an attacker remains undetected within a compromised environment after initial intrusion.
Which tool is BEST suited for capturing and analyzing volatile memory from a compromised Windows system?
Answer: Volatility
Volatility is a memory forensics framework specifically designed to analyze RAM dumps from Windows (and other) systems for malicious artifacts.