1/41
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Security Incident
Security event requiring organized response, such as malware, DDoS, data exfiltration, extortion, or unauthorized access.
Incident Response Lifecycle
Preparation, detection and analysis, containment, eradication, recovery, and post-incident activity.
Preparation
Incident-response phase completed before an incident by establishing resources, contacts, tools, documentation, policies, and procedures.
Incident Go Bag
Prepared collection of hardware and software needed to respond to security incidents, such as specialized laptops, removable media, forensic tools, and imaging equipment.
Incident Preparation Resources
Contact lists, communication methods, network diagrams, server documentation, baselines, critical-file hashes, known-good images, tools, policies, and procedures.
Detection and Analysis
Incident-response phase used to determine whether suspicious events represent a genuine security incident and understand what is happening.
Incident Indicators
Examples include IPS alerts, antivirus detections, unauthorized configuration changes, abnormal traffic, and large outbound data transfers.
Containment
Incident-response phase focused on limiting the scope and spread of an active incident.
Eradication
Incident-response phase focused on eliminating malicious components and conditions that enabled the compromise.
Recovery
Returning affected systems to known-good operation after removing the threat and correcting vulnerabilities.
Recovery Actions
Remove malware, reimage systems, disable compromised accounts, remove attacker accounts, patch vulnerabilities, restore backups, and reinstall known-good software.
Post-Incident Activity
Review performed after an incident to determine what happened, evaluate the response, and improve future plans.
Post-Incident Meeting
Meeting held soon after resolution to review the incident timeline, response effectiveness, missed indicators, and improvements.
Incident Response Sequence
Preparation, detection and analysis, containment, eradication, recovery, then post-incident activity.
Sandbox Analysis
Running suspicious software in an isolated environment to observe its effects without directly exposing production systems.
Sandbox-Aware Malware
Malware that recognizes virtualized or restricted environments and changes its behavior or deletes itself.
Incident Planning
Preparing, documenting, training, and testing response procedures before a real incident occurs.
Tabletop Exercise
Participants verbally walk through an incident scenario and discuss how policies and procedures would be followed.
Simulation
Realistic security exercise that imitates an attack or incident to test people, procedures, and technical controls.
Tabletop vs. Simulation
Tabletop participants discuss what they would do; a simulation actively imitates the event.
Phishing Simulation
Controlled phishing campaign used to measure user behavior and test email and anti-phishing security controls.
Root Cause Analysis
Process of determining the underlying condition or conditions that originally allowed an incident to occur.
Multiple Root Causes
An incident may result from several contributing causes rather than one single failure.
Threat Hunting
Proactively searching systems, configurations, vulnerabilities, and activity for threats before an obvious incident occurs.
Digital Forensics
Acquisition, preservation, analysis, and reporting of digital evidence to understand incidents and potentially support legal proceedings.
Forensic Best Practices
Use established procedures for evidence acquisition, analysis, preservation, documentation, and reporting because evidence may later be used legally.
Legal Hold
Formal request, usually initiated by legal personnel, requiring specified information to be preserved.
Data Custodian
Person responsible for locating, acquiring, and preserving information identified by a legal hold.
ESI
Electronically Stored Information; electronic data preserved or produced for legal purposes.
Evidence Preservation
Maintaining collected information in a pristine and unmodified condition throughout investigation and storage.
Chain of Custody
Documentation showing who accessed or possessed evidence and supporting proof that the evidence remained unchanged.
Digital Chain of Custody Controls
Hashes, digital signatures, and detailed access documentation used to support evidence integrity.
Evidence Acquisition
Process of collecting relevant data from sources such as disk, memory, firmware, files, servers, network devices, firewalls, or virtual systems.
VM Snapshot
Full copy of virtual-machine information that can preserve files and system state for investigation.
Forensic Data Sources
Disk, memory, firmware, files, logs, servers, network devices, firewall logs, VM snapshots, recycle bins, temporary storage, bookmarks, and saved logins.
Forensic Reporting
Documentation describing the incident, evidence-acquisition process, integrity controls, analysis, and conclusions when appropriate.
Original Evidence Preservation
Make copies of digital evidence and perform analysis on copies whenever possible to avoid altering the original.
Live Acquisition
Collecting evidence while a system remains powered on, especially when shutdown could lose volatile data or lock encrypted information.
E-Discovery
Process of collecting, preparing, reviewing, interpreting, and producing electronic documents or information.
E-Discovery vs. Digital Forensics
E-discovery focuses on acquiring and producing requested electronic information; digital forensics analyzes evidence to understand what happened.
Legal Hold vs. Chain of Custody
Legal hold requires specified data to be preserved; chain of custody documents evidence handling and integrity.
Evidence Integrity
Assurance that collected evidence remains the same as when it was originally acquired