Incident Response Activities Quiz

0.0(0)
studied byStudied by 0 people
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/9

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

10 Terms

1
New cards

Which part of the incident response process involves establishing and maintaining the incident response capability as well as setting up an incident response team?

Preparation

2
New cards

In the incident response process, the step that involves identifying and understanding potential incidents to determine their scope, impact, and root cause is a part of the:

Detection and analysis stage

3
New cards

Which of the following answers refer(s) to the containment, eradication, and recovery stage of the incident response process? (Select all that apply)

  • Restoring normal operations

  • Eliminating the threat

  • Mitigating the impact of the incident 

4
New cards

Which stage of the incident response process involves updating incident response plans, policies, and procedures?

Post-incident activity

5
New cards

Which of the answers listed below refers to a discussion-based activity where team members walk through different scenarios to evaluate the incident response plan without activating any systems?

Tabletop exercise

6
New cards

Which of the following answers refers to a more in-depth exercise, which can include activating systems and performing real actions to respond to the incident?

Simulation

7
New cards

 During the post-incident activity stage, this step involves analyzing logs, forensics data, and other evidence to prevent incident reoccurrence.

Root cause analysis

8
New cards

The term "Threat hunting" refers to a proactive search for IoC to identify and address potential threats and vulnerabilities before they can escalate into full-blown incidents.

True

9
New cards

The process of maintaining a documented record of the handling and movement of evidence to ensure its integrity and admissibility in court is called:

Chain of custody

10
New cards

The process of identifying, collecting, and producing electronically stored information with the intent of using it in a legal proceeding or investigation is referred to as:

E-discovery