Incident Response Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response flashcards as text
Which NIST SP 800-61 phase occurs immediately after an incident has been successfully contained?
Answer: Eradication and Recovery
According to NIST SP 800-61, Eradication and Recovery follows the Containment phase, where root causes are removed and systems are restored.
A blue team discovers encoded PowerShell commands in Windows Event Logs. What does this MOST likely indicate?
Answer: Fileless malware or obfuscated attack execution
Encoded PowerShell commands are a common indicator of fileless malware or attackers attempting to obfuscate malicious code from signature detection.
An organization must notify affected customers within 72 hours of discovering a data breach. Which regulation MOST likely mandates this requirement?
Answer: GDPR
GDPR (General Data Protection Regulation) mandates that organizations notify supervisory authorities within 72 hours of becoming aware of a personal data breach.
Which incident categorization approach maps attacker behaviors to a kill chain model to understand attack progression?
Answer: Lockheed Martin Cyber Kill Chain
The Lockheed Martin Cyber Kill Chain maps attacker stages from reconnaissance through actions on objectives to help defenders understand and disrupt attack progression.
During an investigation, an analyst finds that an attacker used legitimate admin credentials to move laterally. Which log would BEST help reconstruct this activity timeline?
Answer: Windows Security Event Logs with authentication events
Windows Security Event Logs capturing authentication events (logon/logoff, credential use) provide the best timeline reconstruction for lateral movement using legitimate credentials.
A security analyst identifies that an attacker achieved persistence through a scheduled task running a malicious executable. Which remediation step is MOST critical?
Answer: Delete the scheduled task AND the malicious executable, then verify no other persistence exists
Full remediation requires removing both the scheduled task trigger and the malicious payload, then hunting for additional persistence mechanisms the attacker may have established.
Which communication practice is MOST important during a major security incident to prevent confusion and misinformation?
Answer: Establishing a single, designated spokesperson for all external communications
A single designated spokesperson ensures consistent, controlled messaging and prevents conflicting or premature information from reaching external parties.