IT Security · CompTIA Security+

Security+ Domain: Operations and Incident Response

Incident response process steps and security operations monitoring concepts tested on the Security+ exam.

39 cards · basic cards · AI-written, checked twice. Edit anything.

Study this set free Get FlashKeepers for iPhone
Define incident response.
A structured set of procedures and capabilities to detect, contain, eradicate, and recover from security events with minimal damage.
What happens during the Preparation phase of incident response?
Tools, training, and documentation are put in place before an incident occurs, including playbooks, monitoring systems, and team readiness.
What is the goal of the Detection phase in incident response?
Identify and recognize that a security incident has occurred using monitoring tools and alerts.
What occurs during the Analysis phase of incident response?
Determine the nature, scope, timeline, and impact of the incident through investigation and evidence collection.
Define containment in incident response.
Actions taken to stop the spread and impact of a security incident, typically divided into short-term containment and long-term containment.
What is the difference between short-term and long-term containment?
Short-term containment stops immediate spread with temporary fixes, while long-term containment removes the threat permanently to prevent recurrence.
What is eradication in incident response?
The process of removing the attacker, malware, and artifacts from the environment to eliminate the root cause of the incident.
What does the Recovery phase accomplish?
Restore systems and data to normal operations, verify functionality, and rebuild confidence that the threat is completely removed.
What is the purpose of the Post-Incident Activity phase?
Conduct a lessons learned meeting, update playbooks, improve processes, and document findings to prevent similar incidents.
Define chain of custody.
A documented record of who collected, handled, and transferred evidence, maintaining its integrity and admissibility in legal proceedings.
What is the primary goal of forensic evidence preservation?
Maintain the integrity and authenticity of evidence so it remains admissible in court and accurately reflects what was found.
What does SIEM stand for?
Security Information and Event Management - a platform that collects, aggregates, and analyzes security event logs from multiple sources.
What is log aggregation?
The process of collecting logs from multiple systems and devices into a central repository for analysis and correlation.
What does SOAR stand for and what does it do?
Security Orchestration, Automation and Response - a platform that automates security response processes and orchestrates tools to reduce manual work.
Define threat hunting.
A proactive process of searching for indicators of compromise and advanced threats that automated systems may have missed.

24 more cards in the app