Incident response process steps and security operations monitoring concepts tested on the Security+ exam.
39 cards · basic cards · AI-written, checked twice. Edit anything.
- Define incident response.
- A structured set of procedures and capabilities to detect, contain, eradicate, and recover from security events with minimal damage.
- What happens during the Preparation phase of incident response?
- Tools, training, and documentation are put in place before an incident occurs, including playbooks, monitoring systems, and team readiness.
- What is the goal of the Detection phase in incident response?
- Identify and recognize that a security incident has occurred using monitoring tools and alerts.
- What occurs during the Analysis phase of incident response?
- Determine the nature, scope, timeline, and impact of the incident through investigation and evidence collection.
- Define containment in incident response.
- Actions taken to stop the spread and impact of a security incident, typically divided into short-term containment and long-term containment.
- What is the difference between short-term and long-term containment?
- Short-term containment stops immediate spread with temporary fixes, while long-term containment removes the threat permanently to prevent recurrence.
- What is eradication in incident response?
- The process of removing the attacker, malware, and artifacts from the environment to eliminate the root cause of the incident.
- What does the Recovery phase accomplish?
- Restore systems and data to normal operations, verify functionality, and rebuild confidence that the threat is completely removed.
- What is the purpose of the Post-Incident Activity phase?
- Conduct a lessons learned meeting, update playbooks, improve processes, and document findings to prevent similar incidents.
- Define chain of custody.
- A documented record of who collected, handled, and transferred evidence, maintaining its integrity and admissibility in legal proceedings.
- What is the primary goal of forensic evidence preservation?
- Maintain the integrity and authenticity of evidence so it remains admissible in court and accurately reflects what was found.
- What does SIEM stand for?
- Security Information and Event Management - a platform that collects, aggregates, and analyzes security event logs from multiple sources.
- What is log aggregation?
- The process of collecting logs from multiple systems and devices into a central repository for analysis and correlation.
- What does SOAR stand for and what does it do?
- Security Orchestration, Automation and Response - a platform that automates security response processes and orchestrates tools to reduce manual work.
- Define threat hunting.
- A proactive process of searching for indicators of compromise and advanced threats that automated systems may have missed.