Block 5 Unit 5 C Flashcards
(8 cards)
______ is a series of analystical steps taken to find out what happened in an incident, to inlude the root cause.
Root Cause Analysis
Name the cyber inident process steps for root cause analysis,
- Gather information, Validate Incident, Determine Oper Imp, Coordinate, Det Report Requirement
During the Gather Information phase, all involved personnel should_____ and_____ all relevant information about the indident for use in incident analysis.
Identify, Collect
During which phase should personnel continuously review the incident to ensure accuracy?
Validate the incident
During the “Determine the Operational Impact” phase, you should coordinate as necessary with the______, the lead CDA unit for Cyber Operations Risk Assessments (CORA), or other organizations for assistance in preparing an impact assessment.
HQ USAF dam ass
A Cyber Incident Report provides a detailed anaylsis that includes the______, ______, _______, & _______.
Affected system, Probable attacker, Attack vector, Tech & oper impacts
Data captured in the______ includes lessons learned, initial root cause, problems with executing courses of action (COAs), missing policies and procedures, and inadequate infrastructure defenses.
Postmortem
What report identifies and incident, group of incidents, or network activity or on a foreign infivdual, group, or organization identified as a threat or potentail threa to DOD networks?
Net Int Rep (NIR)