Ch. 13 Incident Prep and Investigation

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/41

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:50 PM on 7/20/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

42 Terms

1
New cards

business continuity

the ability of an organization to maintain its operations and services in the face of a disruptive event or a major disaster

2
New cards

business continuity planning

process an organization undertakes in advance to determine a plan of action in the event of a disaster

3
New cards

business continuity plan (BSP)

strategic document that provides alternative modes of operation for business activities

4
New cards

continuity of operation planning (COOP)

a federal initative that is intended to encourage organizations to address how critical operations will continue under a broad range of negative circumstances

5
New cards

business impact analysis (BIA)

identifies business processes and functions and then quantifies the impact a loss of these functions may have on business operations

6
New cards

mission-essential function

the activity that serves as the core purpose of the enterprise

7
New cards

single point of failure

component or entity in a system that if it no longer functions, will disable the entire system, is also a goal of a BIA

8
New cards

disaster recovery plan (DRP)

written document that details the process for restoring IT resources following an event that causes a significant disruption in service

9
New cards

incident response plan

set of written instructions for reacting to an information security incident and should contain the following: definitions, incident response teams, and reporting requirements

10
New cards

information security framework

series of documented processes used to define policies and procedures for implementation and management of security controls in an enterprise environment

11
New cards

capacity planning

process of forecasting the need for future resources

12
New cards

people capacity planning

capacity planning that involves calculating future human resources

13
New cards

technology capacity planning

capacity planning for predicting the future number of devices needed

14
New cards

infrastructure capacity planning

capacity planning for predicting the future size of the network

15
New cards

platform diversity

using multiple different devices to host or serve an application or a service

16
New cards

hard disk drives (HDD)

use spinning platters, actuator arms with read/write heads, and motors to store and retrieve data

17
New cards

solid-state drives (SSDs)

stores data on chips instead of magnetic platters

18
New cards

mean time between failures (MTBF)

refer to average amount of time until a component fails, cannot be repaired, or must be replaced

19
New cards

RAID (Redundant Array of Independent Drives)

uses multiple hard drives for increased reliability and performance

20
New cards

storage area network (SAN)

dedicated network storage facility that provides access to data storage over a high-speed network

21
New cards

uninterruptible power supply (UPS)

device that maintains power to equipment in case of an interruption in the primary electrical power source

22
New cards

off-line UPS

if power is interrupted, the UPS quickly begins supplying power to the equipment

23
New cards

on-line UPS

always running off its battery while the main power runs the battery charger - it can cleran the electrical power before reaching the server

24
New cards

hot site

generally run by a commercial disaster recovery service that allows a business to continue computer and network operations to maintain business continuity

25
New cards

cold site

provides office space, but the customer must provide and install all the equipment needed to continue operations

26
New cards

warm site

has all equipment installed but doers not have active internet or telecommunications facilities and does not have current backups of fata

27
New cards

multicloud systems

comprises multiple cloud computing services from different providers, allowing businesses to optimize performance, cost, and redundancy by avoiding reliance on a single vendor.

28
New cards

recovery point objective (RPO)

maximum length of time that an organization can tolerate between copies

29
New cards

recovery time objective (RTO)

length of time it will take to recover the data that has been copied

30
New cards

backup

single scheduled even where data is copiued and then stored so that it can be used in the event of a disaster

31
New cards

snapshot

takes a “picture” of the state of the data repeatedly so that data can be restored from a specific point in time

32
New cards

journaling

makes a copy of the data whenever a change to the data occurs

33
New cards

root-cause analysis (RCA)

process of discovering the origin (root) cause of the security event

34
New cards

SIEM dashboard

can provide information collected from sensors

35
New cards

automated reports

automatically generated summaries of data analysis results to track security events and system performance.

36
New cards

packet capture

protocol that generates information based on capturing packets

37
New cards

forensics

application of science to questions that are of interest to the legal profession

38
New cards

digital forensics

involves the retrieval of difficult-to-obtain data, which is usually hidden, altered, or deleted by the perpetrator

39
New cards

E-discovery

is the electronic counterpart of manually sifting through documents in discovery

40
New cards

acquisition

is the process of collecting, preserving, and analyzing digital evidence for investigation purposes.

41
New cards

order of volatility

refers to the principle that digital evidence should be collected in a specific sequence based on its likelihood of being altered or lost, prioritizing the most volatile data first.

42
New cards

reporting

a detailed written description of the acquisition and analysis of the evidence is required