QS0034-02: Incident Response Plan Flashcards

1
Q

QS0034-01: Incident Response Plan

Which role is responsible for determining the nature and scope of the incident?

A

The Information Security Officer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

QS0034-01: Incident Response Plan

Which role is a central point of contact for all computer incidents?

A

DevOps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

QS0034-01: Incident Response Plan

What are the responsibilities of Application Engineers?

A
  1. Contacts DevOps with any information relating to a suspected breach
  2. Collects pertinent information regarding the incident at the request of the ISO
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

QS0034-01: Incident Response Plan

What are examples of incidents requiring the Incident Team activation?

A
  1. Breach of sensitive data, especially Personal Information
  2. Attacks that impact services or may lead to information that can lead to a breach. For example:
  3. Denial of Service / Distributed Denial of Service
  4. Excessive Port Scans
  5. Firewall Breach
  6. Virus / Malware Outbreak
  7. Disasters that result in potential loss of information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

QS0034-01: Incident Response Plan

What is meant by a Security Breach?

A

A security breach is the unauthorized acquisition of data that compromises the security, confidentiality, or integrity of data maintained by LabLynx.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

QS0034-01: Incident Response Plan

How is the impacted entity notified?

A

Written, or Email notices. At minimum, client facing helpdesk tickets accomplish this.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly