Block 5 Unit 5 C Flashcards

(8 cards)

1
Q

______ is a series of analystical steps taken to find out what happened in an incident, to inlude the root cause.

A

Root Cause Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Name the cyber inident process steps for root cause analysis,

A
  1. Gather information, Validate Incident, Determine Oper Imp, Coordinate, Det Report Requirement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

During the Gather Information phase, all involved personnel should_____ and_____ all relevant information about the indident for use in incident analysis.

A

Identify, Collect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

During which phase should personnel continuously review the incident to ensure accuracy?

A

Validate the incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

During the “Determine the Operational Impact” phase, you should coordinate as necessary with the______, the lead CDA unit for Cyber Operations Risk Assessments (CORA), or other organizations for assistance in preparing an impact assessment.

A

HQ USAF dam ass

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A Cyber Incident Report provides a detailed anaylsis that includes the______, ______, _______, & _______.

A

Affected system, Probable attacker, Attack vector, Tech & oper impacts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data captured in the______ includes lessons learned, initial root cause, problems with executing courses of action (COAs), missing policies and procedures, and inadequate infrastructure defenses.

A

Postmortem

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What report identifies and incident, group of incidents, or network activity or on a foreign infivdual, group, or organization identified as a threat or potentail threa to DOD networks?

A

Net Int Rep (NIR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly