GCGA Ch. 11 Incident Response (ST) Flashcards

(8 cards)

1
Q

Incident response policy

A

defines incident response procedures. Organizations review and update incidents periodically and after reviewing lessons learned after actual incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Communication plan

A

identifies who to inform when an incident occurs. It also outlines the roles and responsibilities of various personnel, including a communication expert that would communicate with the media.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

First step in incident response

A

preparation. It includes creating and maintaining an incident response policy and includes prevention steps such as implementing security controls to prevent malware infections.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Second step in incident response

A

analysis. After detecting a potential incident, personnel perform an analysis to confirm that a security incident is underway.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Third step in incident response

A

containment. Next, they attempt to contain or isolate the problem. Disconnecting a computer from a network will isolate it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Fourth step in incident response

A

eradication attempts to remove all malicious components left after an incident. Recovery restores a system to its original state. Depending on the scope of the incident, administrators might completely rebuild the system, including applying all updates and patches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Reviewing lessons learned

A

A review of lessons learned helps an organization prevent a reoccurrence of an incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Tabletop exercises vs simulations

A

Tabletop exercises are a type of scenario-based training where participants discuss and analyze a hypothetical incident in a non-threatening environment, whereas simulations involve recreating real-world incidents as closely as possible.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly