ISC2 CC Incident Response 1 — Questions and Answers
Question 1: What is the PRIMARY purpose of an incident response plan?
- To prevent all security incidents from occurring
- To provide a structured approach for managing security incidents (Correct answer)
- To replace the need for security monitoring tools
- To document all system vulnerabilities
Correct answer: To provide a structured approach for managing security incidents
An incident response plan provides a structured, predefined approach to detecting, containing, and recovering from security incidents.
Question 2: Which phase of the NIST incident response lifecycle involves identifying whether a security incident has actually occurred?
- Containment
- Eradication
- Detection and Analysis (Correct answer)
- Recovery
Correct answer: Detection and Analysis
The Detection and Analysis phase involves evaluating events to determine whether an actual security incident has occurred and understanding its scope.
Question 3: What does CSIRT stand for in cybersecurity?
- Cyber Security Incident Response Team
- Computer Security Incident Response Team (Correct answer)
- Critical Security Incident Reporting Tool
- Centralized Security Incident Review Team
Correct answer: Computer Security Incident Response Team
CSIRT stands for Computer Security Incident Response Team, the group responsible for coordinating an organization's response to security incidents.
Question 4: Which of the following BEST describes an Indicator of Compromise (IoC)?
- A software patch that fixes a known vulnerability
- A policy defining acceptable use of resources
- A forensic artifact suggesting a system has been breached (Correct answer)
- A tool used to scan networks for open ports
Correct answer: A forensic artifact suggesting a system has been breached
An Indicator of Compromise (IoC) is a forensic artifact or observable evidence that indicates a potential intrusion or security breach has occurred.
Question 5: During which incident response phase would you isolate an affected system from the network?
- Preparation
- Detection and Analysis
- Containment (Correct answer)
- Post-Incident Activity
Correct answer: Containment
Containment is the phase where affected systems are isolated to limit the spread and impact of the incident.
Question 6: What is the FIRST phase of the NIST SP 800-61 incident response lifecycle?
- Detection and Analysis
- Containment, Eradication, and Recovery
- Preparation (Correct answer)
- Post-Incident Activity
Correct answer: Preparation
Preparation is the first phase of the NIST incident response lifecycle, establishing the capability and resources needed before incidents occur.
Question 7: Which document outlines the specific roles, responsibilities, and procedures for responding to security incidents?
- Security Policy
- Business Impact Analysis
- Incident Response Plan (Correct answer)
- Risk Assessment Report
Correct answer: Incident Response Plan
An Incident Response Plan documents the specific procedures, roles, and responsibilities that guide an organization's response to security incidents.
What is the PRIMARY purpose of an incident response plan?