ISP ISP Security Investigations & Incident Response 1 — Questions and Answers
Question 1: Which phase of an incident response plan involves returning systems to normal operations after a security event?
- Identification
- Containment
- Recovery (Correct answer)
- Lessons Learned
Correct answer: Recovery
The recovery phase restores affected systems and verifies they are clean and functional before returning them to production.
Question 2: What is the primary legal reason for maintaining a 'chain of custody' during a security investigation?
- To ensure the fastest possible resolution of the incident
- To preserve the integrity and admissibility of evidence in legal or disciplinary proceedings (Correct answer)
- To assign blame quickly within the organization
- To comply with annual audit requirements
Correct answer: To preserve the integrity and admissibility of evidence in legal or disciplinary proceedings
Proper chain of custody documents who handled evidence and when, ensuring it has not been tampered with and remains legally admissible.
Question 3: A security investigator discovers a suspicious USB drive in a secured area. The FIRST action should be:
- Plug it into a computer to identify its contents
- Photograph it in place, document its location, and secure it as evidence without inserting it into any system (Correct answer)
- Discard it to prevent further risk to the facility
- Hand it to the nearest employee to identify the owner
Correct answer: Photograph it in place, document its location, and secure it as evidence without inserting it into any system
Documenting and preserving the device without connecting it protects both evidence integrity and facility systems from potential malware.
Question 4: An industrial security investigation MUST remain within which legal boundary when interviewing employees?
- Investigators may use physical coercion if the employee refuses to cooperate
- Employees must be informed of their rights, and interviews must comply with applicable labor and employment law (Correct answer)
- Investigators can review employee medical records without consent
- Employees may be detained indefinitely pending investigation outcomes
Correct answer: Employees must be informed of their rights, and interviews must comply with applicable labor and employment law
Industrial security investigations must respect labor laws, privacy rights, and employee rights to counsel to avoid legal liability.
Question 5: Which type of investigation focuses specifically on determining the root cause of a security system failure rather than identifying a perpetrator?
- Criminal investigation
- Administrative investigation
- Root cause analysis (RCA) / technical investigation (Correct answer)
- Grand jury investigation
Correct answer: Root cause analysis (RCA) / technical investigation
RCA investigations analyze system failures, process gaps, or equipment malfunctions to prevent recurrence rather than to assign criminal liability.
Question 6: When must a security incident be reported to the relevant government authority in a cleared industrial facility?
- Only if classified information was confirmed as compromised
- Whenever a reportable security incident occurs, per the facility's reporting requirements and DD Form 577 obligations (Correct answer)
- Only after a full internal investigation is complete
- Never—all incidents are handled internally without government notification
Correct answer: Whenever a reportable security incident occurs, per the facility's reporting requirements and DD Form 577 obligations
Government-cleared facilities are obligated to report security incidents to their Cognizant Security Agency (CSA) as specified in their facility clearance agreement.
Which phase of an incident response plan involves returning systems to normal operations after a security event?