โ† All CySA+ Test Flashcard Decks

Incident Response Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response flashcards as text
  1. During an incident investigation, an analyst finds evidence that data was exfiltrated via DNS queries. Which technique was likely used?

    Answer: DNS tunneling

    DNS tunneling encodes data within DNS query and response packets to covertly exfiltrate information through DNS protocol.

  2. Which chain-of-custody practice is MOST important when collecting digital evidence from a live system?

    Answer: Document every action taken and hash all collected artifacts

    Documenting all actions and hashing artifacts ensures evidence integrity and maintains a defensible chain of custody for legal proceedings.

  3. A SOC analyst identifies a process injecting code into a legitimate Windows process (e.g., svchost.exe). Which MITRE ATT&CK technique does this represent?

    Answer: Process injection

    Process injection is a MITRE ATT&CK technique where adversaries inject malicious code into legitimate running processes to evade detection.

  4. Which log source would be MOST useful for identifying lateral movement via Pass-the-Hash attacks within a Windows environment?

    Answer: Windows Security Event Log (Event ID 4624)

    Windows Security Event ID 4624 (logon events) with Logon Type 3 and NTLM authentication can indicate Pass-the-Hash lateral movement.

  5. An analyst is performing triage on 50 simultaneous alerts. Which approach BEST prioritizes response efforts?

    Answer: Prioritize by asset criticality and potential business impact

    Triaging by asset criticality and business impact ensures the most damaging potential incidents receive immediate attention.

  6. During post-incident analysis, the team discovers the attacker maintained persistence for 90 days before detection. Which term describes this period?

    Answer: Dwell time

    Dwell time refers to the duration an attacker remains undetected within a compromised environment after initial intrusion.

  7. Which tool is BEST suited for capturing and analyzing volatile memory from a compromised Windows system?

    Answer: Volatility

    Volatility is a memory forensics framework specifically designed to analyze RAM dumps from Windows (and other) systems for malicious artifacts.