ISP ISP Security Investigations & Incident Response 2 β Questions and Answers
Question 1: Digital forensic investigators use 'write blockers' to:
- Encrypt evidence drives before analysis
- Prevent any data from being written to an original evidence drive during imaging, preserving its integrity (Correct answer)
- Block malware from writing to the investigator's workstation
- Speed up the forensic imaging process
Correct answer: Prevent any data from being written to an original evidence drive during imaging, preserving its integrity
Write blockers create a one-way barrier so the forensic tool can read the drive without modifying any data on it.
Question 2: In incident response, 'scope creep' during the containment phase refers to:
- Expanding the investigation to include unrelated systems unnecessarily, prolonging downtime (Correct answer)
- Adding additional security analysts to speed up the investigation
- Increasing the severity rating of an incident after new evidence is found
- Documenting more detail than required in the incident report
Correct answer: Expanding the investigation to include unrelated systems unnecessarily, prolonging downtime
Scope creep in containment can take more systems offline than necessary, causing excessive business disruption beyond what the incident warrants.
Question 3: A 'tabletop exercise' in incident response is BEST described as:
- A live simulation where physical intrusion attempts are made on the facility
- A discussion-based exercise where participants walk through a scenario to evaluate plans and decision-making (Correct answer)
- A performance review of the security team's annual metrics
- An unannounced drill designed to test employee reaction without prior notice
Correct answer: A discussion-based exercise where participants walk through a scenario to evaluate plans and decision-making
Tabletop exercises are low-cost, discussion-based sessions that test plans and communication without disrupting operations.
Question 4: Which artifact is MOST useful in reconstructing the timeline of a cyber incident on a Windows system?
- Browser bookmarks folder
- Windows Event Logs (Security, System, Application) (Correct answer)
- Desktop wallpaper settings
- Printer queue history
Correct answer: Windows Event Logs (Security, System, Application)
Windows Event Logs record system events with timestamps, providing the chronological record investigators need to reconstruct an incident.
Question 5: The 'lessons learned' phase of incident response primarily aims to:
- Assign blame and initiate disciplinary actions against responsible personnel
- Identify what worked, what failed, and how to improve processes and controls to prevent recurrence (Correct answer)
- Archive the incident report and close the ticket permanently
- Notify external media about the security breach
Correct answer: Identify what worked, what failed, and how to improve processes and controls to prevent recurrence
Lessons learned transform incident experience into measurable improvements in security posture, policy, and training.
Question 6: When investigating a suspected theft of trade secrets, which type of specialist should typically be involved?
- Marketing analyst
- Legal counsel with IP and employment law expertise (Correct answer)
- Customer service manager
- Payroll administrator
Correct answer: Legal counsel with IP and employment law expertise
IP theft investigations have significant legal dimensions requiring attorneys familiar with trade secret law, employment agreements, and evidence handling.
Digital forensic investigators use 'write blockers' to: