4.8 — Incident Response and Digital Forensics

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/41

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:27 PM on 9/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

42 Terms

1
New cards

Security Incident

Security event requiring organized response, such as malware, DDoS, data exfiltration, extortion, or unauthorized access.

2
New cards

Incident Response Lifecycle

Preparation, detection and analysis, containment, eradication, recovery, and post-incident activity.

3
New cards

Preparation

Incident-response phase completed before an incident by establishing resources, contacts, tools, documentation, policies, and procedures.

4
New cards

Incident Go Bag

Prepared collection of hardware and software needed to respond to security incidents, such as specialized laptops, removable media, forensic tools, and imaging equipment.

5
New cards

Incident Preparation Resources

Contact lists, communication methods, network diagrams, server documentation, baselines, critical-file hashes, known-good images, tools, policies, and procedures.

6
New cards

Detection and Analysis

Incident-response phase used to determine whether suspicious events represent a genuine security incident and understand what is happening.

7
New cards

Incident Indicators

Examples include IPS alerts, antivirus detections, unauthorized configuration changes, abnormal traffic, and large outbound data transfers.

8
New cards

Containment

Incident-response phase focused on limiting the scope and spread of an active incident.

9
New cards

Eradication

Incident-response phase focused on eliminating malicious components and conditions that enabled the compromise.

10
New cards

Recovery

Returning affected systems to known-good operation after removing the threat and correcting vulnerabilities.

11
New cards

Recovery Actions

Remove malware, reimage systems, disable compromised accounts, remove attacker accounts, patch vulnerabilities, restore backups, and reinstall known-good software.

12
New cards

Post-Incident Activity

Review performed after an incident to determine what happened, evaluate the response, and improve future plans.

13
New cards

Post-Incident Meeting

Meeting held soon after resolution to review the incident timeline, response effectiveness, missed indicators, and improvements.

14
New cards

Incident Response Sequence

Preparation, detection and analysis, containment, eradication, recovery, then post-incident activity.

15
New cards

Sandbox Analysis

Running suspicious software in an isolated environment to observe its effects without directly exposing production systems.

16
New cards

Sandbox-Aware Malware

Malware that recognizes virtualized or restricted environments and changes its behavior or deletes itself.

17
New cards

Incident Planning

Preparing, documenting, training, and testing response procedures before a real incident occurs.

18
New cards

Tabletop Exercise

Participants verbally walk through an incident scenario and discuss how policies and procedures would be followed.

19
New cards

Simulation

Realistic security exercise that imitates an attack or incident to test people, procedures, and technical controls.

20
New cards

Tabletop vs. Simulation

Tabletop participants discuss what they would do; a simulation actively imitates the event.

21
New cards

Phishing Simulation

Controlled phishing campaign used to measure user behavior and test email and anti-phishing security controls.

22
New cards

Root Cause Analysis

Process of determining the underlying condition or conditions that originally allowed an incident to occur.

23
New cards

Multiple Root Causes

An incident may result from several contributing causes rather than one single failure.

24
New cards

Threat Hunting

Proactively searching systems, configurations, vulnerabilities, and activity for threats before an obvious incident occurs.

25
New cards

Digital Forensics

Acquisition, preservation, analysis, and reporting of digital evidence to understand incidents and potentially support legal proceedings.

26
New cards

Forensic Best Practices

Use established procedures for evidence acquisition, analysis, preservation, documentation, and reporting because evidence may later be used legally.

27
New cards

Legal Hold

Formal request, usually initiated by legal personnel, requiring specified information to be preserved.

28
New cards

Data Custodian

Person responsible for locating, acquiring, and preserving information identified by a legal hold.

29
New cards

ESI

Electronically Stored Information; electronic data preserved or produced for legal purposes.

30
New cards

Evidence Preservation

Maintaining collected information in a pristine and unmodified condition throughout investigation and storage.

31
New cards

Chain of Custody

Documentation showing who accessed or possessed evidence and supporting proof that the evidence remained unchanged.

32
New cards

Digital Chain of Custody Controls

Hashes, digital signatures, and detailed access documentation used to support evidence integrity.

33
New cards

Evidence Acquisition

Process of collecting relevant data from sources such as disk, memory, firmware, files, servers, network devices, firewalls, or virtual systems.

34
New cards

VM Snapshot

Full copy of virtual-machine information that can preserve files and system state for investigation.

35
New cards

Forensic Data Sources

Disk, memory, firmware, files, logs, servers, network devices, firewall logs, VM snapshots, recycle bins, temporary storage, bookmarks, and saved logins.

36
New cards

Forensic Reporting

Documentation describing the incident, evidence-acquisition process, integrity controls, analysis, and conclusions when appropriate.

37
New cards

Original Evidence Preservation

Make copies of digital evidence and perform analysis on copies whenever possible to avoid altering the original.

38
New cards

Live Acquisition

Collecting evidence while a system remains powered on, especially when shutdown could lose volatile data or lock encrypted information.

39
New cards

E-Discovery

Process of collecting, preparing, reviewing, interpreting, and producing electronic documents or information.

40
New cards

E-Discovery vs. Digital Forensics

E-discovery focuses on acquiring and producing requested electronic information; digital forensics analyzes evidence to understand what happened.

41
New cards

Legal Hold vs. Chain of Custody

Legal hold requires specified data to be preserved; chain of custody documents evidence handling and integrity.

42
New cards

Evidence Integrity

Assurance that collected evidence remains the same as when it was originally acquired