Incident Response Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response flashcards as text
An organization suspects an insider threat is exfiltrating data. Which investigation technique is MOST appropriate before confronting the employee?
Answer: Conduct covert monitoring and log collection under legal authorization
Covert monitoring under proper legal authorization allows evidence collection without alerting the suspect and potentially destroying evidence.
A security team uses the PICERL model for incident response. What does the 'L' represent?
Answer: Lessons Learned
In the PICERL model (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned), 'L' stands for Lessons Learned.
Which of the following BEST describes the purpose of a cyber threat intelligence (CTI) feed in incident response?
Answer: Providing context about attacker TTPs to improve detection and response
CTI feeds provide context about adversary tactics, techniques, and procedures (TTPs) that help analysts detect, investigate, and respond to threats more effectively.
An analyst needs to determine if malware communicated with a command-and-control server. Which artifact provides the MOST direct evidence?
Answer: Firewall outbound connection logs
Firewall outbound connection logs directly show network communication attempts, including connections to C2 servers.
During eradication, an analyst must ensure all persistence mechanisms are removed. Which location should be checked FIRST on a compromised Windows system?
Answer: Registry run keys and startup locations
Registry run keys and startup locations are the most common persistence mechanisms used by malware to survive system reboots.
A company's IR plan calls for activating a 'war room' during a major incident. What is the PRIMARY benefit of this approach?
Answer: It centralizes decision-making and communication among key stakeholders
A war room centralizes key personnel and communications, enabling faster coordinated decision-making during high-pressure incidents.
Which type of malware analysis involves running a suspicious file in an isolated environment to observe its behavior without risking production systems?
Answer: Dynamic analysis
Dynamic analysis executes malware in a sandboxed environment to observe real-time behaviors such as network connections, file creation, and registry changes.