Incident Response Flashcards

1
Q

What is Incident Reponse?

A

IR is the process of taking organized and careful steps when reacting to a security incident. Starts from identifying and reporting an incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the responsibilities of IH&R team?

A

Incident Handling and Response Team is a group of specialized people who respond, remediate, mitigate, recover and communicate the impact of the incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What roles can be identified within the IH&R team?

A
  • Management (decision-maker)
  • Information Security Team (incident discovery and containment)
  • IT Staff (system/network administrator)
  • Physical Security Staff
  • Attorney (legal advice)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who’s the First Responder?

A

The person who first starts IR process and brings the incident to the attention of others. It may or not be the person you actually reported the incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Responsibilities of first responder

A

Reporting, alerting, containing, identifying, collecting, protecting, documenting; preserving and packaging evidences.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Why having an IH&R process is important?

A

Planned methodology that produces consistent, repeatable results that you can defend both process-wise and legally.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Summarize IH&R process flow.

A
  1. Preparation for incident handling and response.
  2. Incident recording and assignment.
  3. Incident triage.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is included in preparation for incident handling and response?

A

Scope, management approval, funding, developing the team.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the most important features of training IH&R personnel?

A
  • Teach personnel the IR plan
  • Rotate team members to build confidence in various roles
  • Mock drills
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is included in the incident triage?

A
  • Analysis and validation
  • Classification
  • Prioritization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly