Incident Response Team + Exercises + Netflow

0.0(0)
studied byStudied by 0 people
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/8

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

9 Terms

1
New cards

A member of management

or organizational leadership

2
New cards

Information security

staff members

3
New cards

Technical experts

such as systems administrators, developers, or others from disciplines throughout the organization

4
New cards

Communications

and public relations staff

5
New cards

Legal and human resources (HR)

staff may be included in some, but not all, incidents

6
New cards

Law enforcement

is sometimes added to a team, but in most cases only when specific issues or attacks require their involvement

7
New cards

Tabletop exercises

are used to talk through processes. Team members are given a scenario and are asked questions about how they would respond, what issues may arise, and what they would need to do to accomplish the tasks they are assigned in the IR plan. ___ ___ can resemble a brainstorming session as team members think through a scenario and document improvements in their responses and overall IR plan

8
New cards

Simulations

can include a variety of types of events. Exercises may simulate individual functions or elements of the plan, or only target specific parts of an organization. They can also be done at full scale, involving the entire organization in the exercise. It is important to plan and execute ____ in a way that ensures that all participants know that they are engaged in an exercise so that no actions are taken outside of the exercise environment

9
New cards

NetFlow

is a network protocol developed by Cisco that allows for the collection and analysis of network traffic data. It provides visibility into the types of traffic, the sources and destinations of that traffic, and the amount of data being transferred. ___ helps in monitoring and understanding network activity, which is crucial for both security and network performance purposes.