1/17
Flashcards covering the key concepts related to Incident Response Activities.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Effective incident response is governed by formal policies and __________, setting out roles and responsibilities for an incident response team.
procedures
A cybersecurity incident refers to either a successful or attempted violation of the security properties of an asset, compromising its __________, integrity, or availability.
confidentiality
CompTIA's incident response lifecycle is a __________-step process.
seven
The first step in the incident response process is __________, which makes the system resilient to attack.
Preparation
Incident response aims to secure data while limiting the immediate impact on __________ and business partners.
customers
The analysis phase determines whether an incident has taken place and performs __________ to assess severity.
triage
The phase that limits the scope and magnitude of the incident is called __________.
Containment
After containment, the next step is __________, which removes the cause and restores the affected system to a secure state.
Eradication
The __________ phase reintegrates the system into the business process it supports after the cause of the incident has been eradicated.
Recovery
__________ learned analyzes the incident and responses to identify improvements.
Lessons
Cybersecurity infrastructure includes hardware and software tools that facilitate incident detection, digital __________, and case management.
forensics
An incident response team can also be referred to as a __________, CSIRT, or CERT.
CIRT
The incident response plan (IRP) lists procedures, contacts, and resources available to responders for various __________ categories.
incident
Detection is the process of correlating events from network and __________ data sources to identify incidents.
system
The 'Five Whys' model is a method used in root cause __________ to understand how an incident was able to occur.
analysis
Testing and training are critical to validate the preparation process and ensure readiness to perform __________ response.
incident
Threat hunting utilizes insights gained from threat __________ to proactively discover evidence of TTPs within the network.
intelligence
During containment, some issues facing the CIRT include the nature of damage and what __________ are available.
countermeasures