Security Risk Management and Incident Response Flashcards
7 cards from real ICS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Risk Management and Incident Response flashcards as text
The concept of 'tabletop exercises' in ICS incident response refers to:
Answer: Discussion-based simulations where participants walk through an incident scenario without activating actual response procedures
Tabletop exercises use scenario-based discussions to evaluate the incident response plan, test decision-making, and identify gaps without disrupting live operations.
When an ICS organization transfers risk by purchasing cyber insurance, which residual obligation remains?
Answer: The organization must still implement reasonable security controls as required by the insurance policy
Cyber insurance policies require the insured to maintain minimum security standards; failing to do so can void coverage, meaning organizations still must manage the risk.
Which metric BEST measures the effectiveness of an ICS incident response program over time?
Answer: Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) trends across incidents
MTTD and MTTR measure how quickly threats are detected and contained, directly reflecting the operational effectiveness of the incident response program.
During the 'eradication' phase of ICS incident response, the primary goal is to:
Answer: Remove all traces of the attacker and eliminate the root cause from affected systems
Eradication focuses on removing malware, closing attack vectors, and eliminating the root cause to prevent reinfection before recovery begins.
A facility uses the MITRE ATT&CK for ICS framework during incident response. Its primary value is:
Answer: Offering a common taxonomy of adversary tactics, techniques, and procedures (TTPs) specific to ICS environments
MITRE ATT&CK for ICS provides a structured knowledge base of ICS-specific adversary behaviors, enabling teams to map observed activity to known attack patterns.
In the context of ICS risk management, 'inherent risk' is best defined as:
Answer: The raw risk level that exists before any controls or mitigations are applied
Inherent risk represents the natural exposure to a threat before any security controls are applied, establishing the baseline for risk treatment decisions.
An ICS organization must notify the Department of Homeland Security (DHS) CISA about a significant cyber incident within 72 hours under which regulation?
Answer: CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA requires critical infrastructure entities to report significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours.