Security incident response planning and program development concepts tested on the CISM exam.
36 cards · basic cards · AI-written, checked twice. Edit anything.
- What is incident response?
- A systematic process for identifying, investigating, containing, and recovering from security incidents.
- Name the four phases of incident response.
- Preparation, Detection and Analysis, Containment/Eradication/Recovery, Post-Incident Activities.
- What is the primary goal of the preparation phase?
- Establish the capability and readiness to respond to security incidents effectively.
- What occurs in the detection and analysis phase?
- Incidents are identified, confirmed, and investigated to determine their scope and impact.
- What is the purpose of containment?
- To stop the active attack and limit the scope and damage of the incident.
- What is eradication in incident response?
- Removing the attacker's access, tools, backdoors, and malware from all affected systems.
- What is the recovery phase?
- Restoring systems and data to normal operations and verifying they function correctly.
- What is root cause analysis?
- Determining the underlying technical, process, or human factors that allowed the incident to occur.
- When should the post-incident review meeting occur?
- Within days or weeks of incident resolution while details are fresh.
- What is an incident response plan?
- A documented, tested procedure that defines roles, processes, and communication protocols for responding to incidents.
- What is the purpose of incident classification?
- To categorize incidents by type, severity, and impact to enable prioritized and appropriate response.
- Name three critical roles in an incident response team.
- Incident manager, technical analyst, and communications/public relations lead.
- What is forensic evidence?
- Data and materials collected and preserved in a manner that maintains integrity and admissibility in legal proceedings.
- What is chain of custody?
- Documentation of who handled evidence, when they handled it, and what actions they performed, maintaining its integrity.
- What is a containment strategy?
- The planned approach to stopping an active incident from spreading to additional systems or data.