Detection and Response Flashcards

(7 cards)

1
Q

Incident

A

An occurrence that actually or imminently jeopardizes, without lawful authority, confidentiality, integrity or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Event

A

An observable occurrence on a network, system to device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The 5 W’s of an incident ?

A
  1. Who triggered the incident?
  2. What happened ?
  3. When the incident took place?
  4. Where the incident took place?
    5.Why the incident occured?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Incident handlers journal?

A

A form of documentation used during an incident response.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Computer security incident response teams (CSIRT)

A

A specialized group of security professionals that are trained in incident management and response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Roles in CSIRT

A

1.Security analyst
2. Technical lead
3. Incident Cordinator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly