CJIS Incident Response & System Auditing — Questions and Answers
Question 1: What is the first step in incident response?
- Ignore incident
- Identify and report (Correct answer)
- Delete evidence
- Delay response
Correct answer: Identify and report
The first and most critical step in incident response is to identify that an incident has occurred and promptly report it through established channels. This immediate recognition and notification enable a rapid and appropriate response, preventing further damage and initiating the necessary steps to contain and resolve the situation.
Question 2: Why is an incident response plan important?
- No plan needed
- Structured breach response (Correct answer)
- Confuses teams
- Avoids reporting
Correct answer: Structured breach response
An incident response plan is vital because it provides a structured and predefined framework for handling security breaches or other incidents. This plan outlines clear roles, responsibilities, and procedures, ensuring an organized, efficient, and effective response that minimizes impact and facilitates recovery.
Question 3: What is system auditing used for?
- Hide activity
- Review activity (Correct answer)
- Ignore logs
- Speed systems
Correct answer: Review activity
System auditing is primarily used to review and verify activity within a system, including user actions, access attempts, and system events. By systematically examining these records, auditors can detect unauthorized access, policy violations, and suspicious behavior, ensuring the integrity and security of the system.
Question 4: How often should audits be conducted?
- Once only
- Regularly (Correct answer)
- Never
- Only after incidents
Correct answer: Regularly
Audits should be conducted regularly to maintain continuous security posture and compliance. Regular checks help identify vulnerabilities, ensure adherence to policies, and detect potential threats or anomalies before they can escalate into major incidents, thereby providing ongoing assurance and risk mitigation.
Question 5: What is a key component of incident documentation?
- Minimal notes
- Detailed records (Correct answer)
- No documentation
- Ignore incidents
Correct answer: Detailed records
Detailed records are a key component of incident documentation because they provide a comprehensive and accurate account of the incident, including its timeline, impact, and all actions taken. This thorough documentation is essential for post-incident analysis, legal compliance, and improving future response strategies.
Question 6: Who should be notified in a major security incident?
- Ignore notification
- Notify authorities (Correct answer)
- Tell media first
- Avoid communication
Correct answer: Notify authorities
In a major security incident, especially one involving sensitive criminal justice information, notifying authorities is often a legal and ethical requirement. This ensures proper investigation, compliance with reporting mandates, and allows for potential assistance from law enforcement or regulatory bodies in mitigating the incident and protecting affected parties.
Question 7: Why is root cause analysis important?
- Ignore causes
- Find root cause (Correct answer)
- Blame users
- Delay fixes
Correct answer: Find root cause
Root cause analysis is crucial because it goes beyond addressing the symptoms of an incident to identify its fundamental underlying cause. By understanding why an incident truly happened, organizations can implement effective preventative measures to avoid similar occurrences in the future, significantly strengthening their overall security posture.
Question 8: What is the role of log review in auditing?
- Ignore logs
- Detect suspicious activity (Correct answer)
- Delete logs
- Speed operations
Correct answer: Detect suspicious activity
Log review plays a critical role in auditing by allowing security personnel to examine system-generated records of events and user activities. Regularly reviewing these logs helps detect unusual patterns, unauthorized access attempts, or other suspicious activities that could indicate a security breach or policy violation, enabling timely intervention.
Question 9: How can incident response be improved?
- No drills
- Regular drills and updates (Correct answer)
- Ignore updates
- Delay training
Correct answer: Regular drills and updates
Incident response capabilities are significantly improved through regular drills and exercises, which allow teams to practice their roles and identify weaknesses in the plan. Continuous updates to the plan, based on lessons learned from drills and evolving threats, ensure its ongoing effectiveness and relevance in a dynamic threat landscape.
What is the first step in incident response?