Incident Response

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/43

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:12 PM on 8/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

44 Terms

1
New cards

Incident Response

Outlines a structured approach to manage and mitigate security incidents effectively. Minimize impact, reduce response time, hasten recovery

2
New cards

Incident

Act of violating an explicit or implied security policy

3
New cards

Incident Response Procedures

Guidelines for handling security incidents

4
New cards

Incident Response Steps

Preparation, Detection, Analysis, Containment, Eradication, Recovery, Post-Incident Activity

5
New cards

Preparation

Get everything ready for future incidents. Gets an organization ready for future incidents. Focuses on making systems resilient to attacks by hardening systems and networks

6
New cards

Detection

Determines if a security incident has occurred. Identifies a security incident

7
New cards

Eradication

Starts after containment and aims to remove malicious activity from the system or network

8
New cards

Analysis

Involves a thorough examination of the incident

9
New cards

Containment

Limits the incidents impact by securing data and protecting business operations

10
New cards

Recovery

Restores systems and services to their normal secure state

11
New cards

Post-Incident Activity

Happens after containment, eradication, and full system recovery. Analyze the situation and see if you effectively taken care of the incident

12
New cards

Root cause analysis

Identifies the incident’s source and how to prevent it in the future. Define/scope the incident, Determine what caused the incident, Identify an effective solution, implement and track solutions

13
New cards

Lessons Learned Process

Documents experienced during incidents in a formalized way

14
New cards

After-action Report

Collects formalized information about what occurred

15
New cards

Incident Response Teams

The core team includes cybersecurity professionals with incident response experience

16
New cards

Threat Hunting

Cybersecurity method for finding hidden threats not caught by regular security monitoring

17
New cards

Threat Hunting Steps

Establish a Hypothesis, Profiling Threat Actors and Activities, Threat Hunting Process

18
New cards

Benefits of Threat Hunting

Improves detection capabilities by identifying threats that bypass existing defenses. Enhances threat intelligence by correlating external threat feeds with internal logs. Provides actionable intelligence to strengthen security measures

19
New cards

Advisories and Bulletins

Published by veneers and security researchers when new TTPs and vulnerabilities are discovered

20
New cards

Intelligence Fusion and Threat Data

Use SIEM and analysis platforms to spot concerns in the logs and real-world security threats

21
New cards

Define the scope of the incident

What is the cause and how big is the impact?

22
New cards

Determine the Causal Relationship

Understand how the incident occurred, such as through malware

23
New cards

Identify an effective solution

Find solutions to prevent the incident from recurring

24
New cards

Implement and Track Solutions

Execute the solutions and ensure the incident is fully resolved

25
New cards

No-Blame Approach

Can encourage open reporting to improve cybersecurity. Root Cause Analysis should not assign blame to individuals or teams.

26
New cards

Training

Ensures staff grasp processes and priorities for incident responses. Tailor it to all employees based on needs. Base it on lessons learned from past incidents

27
New cards

Testing

Practical exercise of incident response procedures. Costly and can be complex. Use a tabletop exercise, Penetration Test, or a Simulation

28
New cards

Tabletop Exercise (TTX)

Exercises simulate incidents within a control framework

29
New cards

Simulation

Replicates real incidents for hands on experience

30
New cards

Digital Forensics

Systematic process of investigating and analyzing digital devices and data to uncover evidence for legal purposes. Identification, Collection, analysis, and reporting

31
New cards

Identification

Focus on scene safety, prevention of evidence contamination, and scope determination. Secure the scene, preserve evidence, and document the scene. Identify where relevant data might be stored

32
New cards

Collection

Refers to the process of gathering, preserving, and documenting physical or digital evidence in various fields

33
New cards

Order of Volitility

Dictates the sequence in which data sources should be collected and preserved based on their susceptibility to be modification or loss. First collect system memory, data from system state, storage device, network traffic and logs, remotely stored or archived data

34
New cards

End User Training

Report incidents and remedial training for people who make mistakes

35
New cards

Chain of Custody

Documented and verifiable record that tracks the handling, transfer, and preservation of digital evidence from the moment it is collected until it is presented in a court of law

36
New cards

Disk Imaging

Involves creating a bit-by-bit or logical copy of a storage device, preserving its entire content, including deleted files and unallocated space

37
New cards

File Carving

Focuses on extracting files and data fragments from storage media without relying on the file system

38
New cards

Analysis for digital forensics

Systematically scrutinizing the data to uncover relevant information

39
New cards

Reporting for digital forensics

Involves documenting the findings, processes, and methodologies used during a digital forensics investigations

40
New cards

Legal Hold

Formal notification that instructs employees to preserve all potentially relevant event electronic data, documents, and records

41
New cards

E-Discovery (Electronic Discovery)

Process of identifying, collecting, and presenting electronically stored information for potential legal proceedings. Involves searching, analyzing, and formatting electronic data for litigation

42
New cards

Ethical considerations for digital forensics

Avoiding Bias, Repeatable Actions, Evidence Preservation

43
New cards

Data Acquisition

The method and tools used to create a forensically sound copy of the data from a source device, like system memory or a hard disk

44
New cards