Domain 4: Incident Response and Recovery

0.0(0)
studied byStudied by 0 people
GameKnowt Play
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/50

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

51 Terms

1
New cards

What is the first phase of the incident response lifecycle?

Preparation — defining roles, training, policies, and tools.

2
New cards

What phase involves detecting incidents using monitoring tools like IDS and SIEM?

Detection and Analysis.

3
New cards

During which phase is the impact of an incident limited by isolating systems or blocking traffic?

Containment.

4
New cards

What phase involves removing the root cause of an incident?

Eradication.

5
New cards

What phase restores affected systems to normal operation after an incident?

Recovery.

6
New cards

What phase includes lessons learned and updating policies after an incident?

Post-Incident Activities.

7
New cards

What is the primary purpose of the preparation phase?

To ensure readiness through defined roles, training, and tools.

8
New cards

What type of monitoring tool detects suspicious activity but does not block it?

Intrusion Detection System (IDS).

9
New cards

What type of monitoring tool detects and actively blocks threats?

Intrusion Prevention System (IPS).

10
New cards

What legal system deals with disputes between private parties in cybersecurity?

Civil Law.

11
New cards

What is the burden of proof in civil law?

Preponderance of evidence (more likely than not).

12
New cards

What legal system addresses offenses against the state like hacking and fraud?

Criminal Law.

13
New cards

What is the burden of proof in criminal law?

Beyond a reasonable doubt.

14
New cards

Which law governs regulatory compliance enforced by government agencies (e.g., HIPAA, GDPR)?

Administrative Law.

15
New cards

What ethical principle requires protecting forensic data and findings?

Confidentiality.

16
New cards

What ethical principle requires investigators to remain unbiased?

Impartiality.

17
New cards

What ethical principle requires evidence collection and reporting to be accurate and untampered?

Integrity.

18
New cards

Who is responsible for securing the scene and avoiding contamination in forensic investigations?

First Responder.

19
New cards

What is the term for prioritizing evidence collection and preservation in investigations?

Triage.

20
New cards

What documentation ensures evidence handling is tracked and admissible in court?

Chain of Custody.

21
New cards

What is the legal requirement for evidence to be accepted in court?

Admissibility.

22
New cards

What challenge arises when cyber incidents cross multiple countries?

Cross-Jurisdictional Challenges.

23
New cards

What does BCP stand for?

Business Continuity Plan.

24
New cards

What does DRP stand for?

Disaster Recovery Plan.

25
New cards

What type of backup copies all data?

Full Backup.

26
New cards

What backup copies data changed since the last backup, full or incremental?

Incremental Backup.

27
New cards

What backup copies data changed since the last full backup?

Differential Backup.

28
New cards

What is an RTO in disaster recovery?

Recovery Time Objective — maximum allowable downtime.

29
New cards

What is an RPO in disaster recovery?

Recovery Point Objective — maximum acceptable data loss.

30
New cards

What is MTD in disaster recovery?

Maximum Tolerable Downtime — total outage limit.

31
New cards

What type of disaster recovery site is fully equipped and operational for immediate failover?

Hot Site.

32
New cards

What type of disaster recovery site is partially equipped and ready with data backups?

Warm Site.

33
New cards

What type of disaster recovery site has no equipment and requires setup time?

Cold Site.

34
New cards

What is a tabletop disaster recovery test?

A scenario-based discussion and role-play of recovery plans.

35
New cards

What is a walkthrough disaster recovery test?

Step-by-step review of plans by team members.

36
New cards

What is a simulation disaster recovery test?

A realistic test of recovery without disrupting operations.

37
New cards

What is a parallel disaster recovery test?

Running recovery systems alongside production without impact.

38
New cards

What is a full interruption disaster recovery test?

Shutting down production systems to test recovery.

39
New cards

What is the purpose of containment during incident response?

To limit the damage caused by an incident.

40
New cards

What does eradication focus on during incident response?

Removing the cause of the incident.

41
New cards

What is the importance of recovery in incident response?

Restoring affected systems and services to normal operation.

42
New cards

What is a critical activity after recovery in incident response?

Monitoring for signs of incident recurrence.

43
New cards

Why is post-incident documentation important?

To record the incident details and improve future response.

44
New cards

What role does training play in incident response preparation?

Ensures team readiness and awareness of roles.

45
New cards

What is the difference between IDS and IPS?

IDS detects and alerts; IPS detects and blocks threats.

46
New cards

What is the significance of chain of custody in forensic investigations?

It preserves the integrity and admissibility of evidence.

47
New cards

What is the goal of business continuity planning?

To ensure essential business functions continue during and after a disruption.

48
New cards

What is the main focus of disaster recovery planning?

To restore IT systems and data after an incident.

49
New cards

What is the difference between incremental and differential backups?

Incremental backs up changes since last backup; differential backs up changes since last full backup.

50
New cards

Why are disaster recovery tests important?

They verify the effectiveness of recovery plans and preparedness.

51
New cards