Lesson 12 - Group 1: Incident Response

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/20

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:31 PM on 7/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

21 Terms

1
New cards
What is the incident-response process order shown on page 4?
Preparation, detection, analysis, containment, eradication, recovery, and lessons learned.
2
New cards
Preparation
Establishing the cybersecurity infrastructure, personnel, plans, communication methods, and authority needed to respond to incidents.
3
New cards
Cyber Incident Response Team
The group responsible for reporting, categorizing, prioritizing, analyzing, and responding to incidents; related names include CIRT, CERT, CSIRT, and SOC.
4
New cards
Triage
Reporting, categorizing, and prioritizing reported security events and incidents.
5
New cards
What nontechnical roles may participate in incident response?
Management, legal, Human Resources, and marketing.
6
New cards
Communication plan
Defines trusted contacts, stakeholder communications, notification procedures, and how incident information should be shared.
7
New cards
Why should incident information be shared on a need-to-know basis?
To prevent inadvertent disclosure of sensitive incident information.
8
New cards
Out-of-band communication
Communication through a separate channel to avoid alerting an intruder who may be monitoring normal systems.
9
New cards
IRP
Incident Response Plan.
10
New cards
Detection
Identifying possible incidents through logs, alerts, baseline deviations, manual inspection, notifications, public reporting, or whistleblowing.
11
New cards
First responder
The CIRT member who takes charge of a reported incident.
12
New cards
Analysis
Classifying, prioritizing, and determining an incident’s impact, scope, category, detection time, and expected recovery time.
13
New cards
Playbook
A documented set of response actions for a particular incident type or scenario.
14
New cards
Containment
Limiting incident damage while considering loss control, available countermeasures, and evidence preservation.
15
New cards
Isolation-based versus segmentation-based containment
Isolation removes an affected system from other systems; segmentation restricts communication between network areas.
16
New cards
Eradication and recovery
Reconstituting affected systems, reaудiting security controls, restoring operations, and notifying affected parties.
17
New cards
Lessons learned
A post-incident process that reviews the timeline, reports findings, and identifies improvements.
18
New cards
Five whys
A root-cause analysis method that repeatedly asks why an incident or failure occurred.
19
New cards
What testing methods are listed for incident response?
Tabletop exercises, walkthroughs, and simulations.
20
New cards
Tabletop versus walkthrough versus simulation
A tabletop discusses a facilitator-provided scenario without live systems; a walkthrough demonstrates response actions; a simulation uses a simulated intrusion, such as one performed by a red team.
21
New cards
Threat hunting
A proactive process that uses threat intelligence and security data to search for threats before or outside normal reactive incident respons