ISC2 CC Incident Response 2 — Questions and Answers
Question 1: What is the goal of the Eradication phase in incident response?
- Documenting lessons learned from the incident
- Removing the root cause and malicious artifacts from affected systems (Correct answer)
- Restoring systems to normal operations
- Notifying management of the incident
Correct answer: Removing the root cause and malicious artifacts from affected systems
The Eradication phase focuses on removing malware, closing exploited vulnerabilities, and eliminating the root cause of the incident.
Question 2: 'Lessons learned' activities primarily occur during which phase of the incident response lifecycle?
- Preparation
- Containment
- Recovery
- Post-Incident Activity (Correct answer)
Correct answer: Post-Incident Activity
Post-Incident Activity includes conducting lessons learned meetings to evaluate the response, improve processes, and update documentation for future incidents.
Question 3: Which of the following BEST represents a security incident?
- A scheduled system maintenance window
- An authorized penetration test discovering vulnerabilities
- Unauthorized access to sensitive customer records (Correct answer)
- A user forgetting their password
Correct answer: Unauthorized access to sensitive customer records
Unauthorized access to sensitive customer records is an actual security incident because it violates the confidentiality of protected information without authorization.
Question 4: What term describes prioritizing security incidents based on their severity and potential impact?
- Escalation
- Triage (Correct answer)
- Remediation
- Forensics
Correct answer: Triage
Triage is the process of evaluating and prioritizing incidents based on their potential impact and urgency so the most critical issues are addressed first.
Question 5: Which of the following BEST describes the Recovery phase of incident response?
- Identifying the root cause of the incident
- Notifying law enforcement about the breach
- Restoring affected systems to normal and verified operation (Correct answer)
- Capturing and preserving digital evidence
Correct answer: Restoring affected systems to normal and verified operation
The Recovery phase involves restoring affected systems to full, verified operational status after the incident has been contained and eradicated.
Question 6: What is the purpose of maintaining a chain of custody during incident response?
- To ensure all employees are aware of the incident
- To track evidence handling and preserve its integrity for legal proceedings (Correct answer)
- To document a timeline of system configuration changes
- To assign accountability for causing the security incident
Correct answer: To track evidence handling and preserve its integrity for legal proceedings
Chain of custody documents the handling, transfer, and storage of evidence to ensure its integrity and admissibility in legal or disciplinary proceedings.
Question 7: Which type of incident response team is a full-time, permanently established team within an organization?
- Virtual CSIRT
- Outsourced CSIRT
- Distributed CSIRT
- Dedicated CSIRT (Correct answer)
Correct answer: Dedicated CSIRT
A Dedicated (Permanent) CSIRT is a full-time team with incident response as its primary mission, always available within the organization.
What is the goal of the Eradication phase in incident response?