4.8 Explain Appropriate Incident Response Activities

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/17

flashcard set

Earn XP

Description and Tags

Flashcards covering the key concepts related to Incident Response Activities.

Last updated 6:48 PM on 3/23/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

18 Terms

1
New cards

Effective incident response is governed by formal policies and __________, setting out roles and responsibilities for an incident response team.

procedures

2
New cards

A cybersecurity incident refers to either a successful or attempted violation of the security properties of an asset, compromising its __________, integrity, or availability.

confidentiality

3
New cards

CompTIA's incident response lifecycle is a __________-step process.

seven

4
New cards

The first step in the incident response process is __________, which makes the system resilient to attack.

Preparation

5
New cards

Incident response aims to secure data while limiting the immediate impact on __________ and business partners.

customers

6
New cards

The analysis phase determines whether an incident has taken place and performs __________ to assess severity.

triage

7
New cards

The phase that limits the scope and magnitude of the incident is called __________.

Containment

8
New cards

After containment, the next step is __________, which removes the cause and restores the affected system to a secure state.

Eradication

9
New cards

The __________ phase reintegrates the system into the business process it supports after the cause of the incident has been eradicated.

Recovery

10
New cards

__________ learned analyzes the incident and responses to identify improvements.

Lessons

11
New cards

Cybersecurity infrastructure includes hardware and software tools that facilitate incident detection, digital __________, and case management.

forensics

12
New cards

An incident response team can also be referred to as a __________, CSIRT, or CERT.

CIRT

13
New cards

The incident response plan (IRP) lists procedures, contacts, and resources available to responders for various __________ categories.

incident

14
New cards

Detection is the process of correlating events from network and __________ data sources to identify incidents.

system

15
New cards

The 'Five Whys' model is a method used in root cause __________ to understand how an incident was able to occur.

analysis

16
New cards

Testing and training are critical to validate the preparation process and ensure readiness to perform __________ response.

incident

17
New cards

Threat hunting utilizes insights gained from threat __________ to proactively discover evidence of TTPs within the network.

intelligence

18
New cards

During containment, some issues facing the CIRT include the nature of damage and what __________ are available.

countermeasures