Incident Response Process Flashcards

(10 cards)

1
Q

What is an Incident?

A

Act of violating a security policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the 1st step of Incident Response - Preparation?

A

Involves hardening systems and networks to resist attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the 2nd step of Incident Response - Detection?

A

Identifies a security incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the 3rd step of Indcident Response - Analysis?

A

Thoroughly examines and evaluates the incident

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the 4th step of Incident Response - Containment?

A

Prevents the incident from spreading by securing data and minimizing business impact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the 5th step of Incident Response - Eradication?

A

Focuses on removing malicious activity from systems or networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the 6th step of Incident Response - Recovery?

A

Restores affected systems and services to their secure state

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the 7th step of Incident Response - Post-Incident Activity?

A

Identifies the initial incident source and makes improvements to prevent future incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the Lessons Learned Process?

A

Documents experiences during incidents in a formalized way

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does an After-action report do?

A

Collects formalized information about what occurred

How well did you know this?
1
Not at all
2
3
4
5
Perfectly