CCST - Cisco Certified Support Technician Security Incident Handling Process Questions and Answers 1 — Questions and Answers
Question 1: Which of the following activities is a critical component of the 'Preparation' phase of the security incident handling process, according to the NIST framework?
- Analyzing system logs to determine the scope of a breach.
- Restoring data from backups after a ransomware attack.
- Establishing and training a Computer Security Incident Response Team (CSIRT). (Correct answer)
- Disconnecting an infected machine from the network.
Correct answer: Establishing and training a Computer Security Incident Response Team (CSIRT).
The 'Preparation' phase involves all the proactive steps taken before an incident occurs to ensure the organization is ready to respond. Establishing and training a CSIRT is a fundamental preparatory step, along with creating policies, acquiring necessary tools, and performing risk assessments.
Question 2: A support technician observes alerts from a SIEM tool indicating multiple failed login attempts on a critical server, followed by a successful login from an unrecognized IP address. Which phase of the incident handling process has just begun?
- Containment
- Detection and Analysis (Correct answer)
- Recovery
- Preparation
Correct answer: Detection and Analysis
The 'Detection and Analysis' phase begins when potential signs of an incident are discovered. This involves detecting anomalies (the alerts) and then analyzing them to determine if a security incident has actually occurred, which is the immediate next step for the technician.
Question 3: During a malware outbreak, a security analyst instructs a technician to immediately disconnect the infected computers from the corporate network. This action is a primary example of which incident response phase?
- Eradication
- Recovery
- Lessons Learned
- Containment (Correct answer)
Correct answer: Containment
Containment strategies are actions taken to stop the incident from causing further damage and to prevent it from spreading to other systems. Disconnecting affected machines is a classic short-term containment step to isolate the threat.
Question 4: After a security incident has been contained and the immediate threat is neutralized, a technician is tasked with re-imaging an affected workstation from a known good gold image and ensuring all security patches are applied. This activity belongs to which two connected phases of the incident response lifecycle?
- Preparation and Identification
- Eradication and Recovery (Correct answer)
- Detection and Analysis
- Containment and Lessons Learned
Correct answer: Eradication and Recovery
This action serves two purposes. 'Eradication' involves removing the root cause of the incident (the malware is wiped out by re-imaging). 'Recovery' involves restoring the affected systems back to normal operation so business can resume, which includes applying patches to prevent reinfection.
Question 5: A company has just recovered from a major data breach. The management team holds a meeting with the IT and security staff to review the incident timeline, discuss what went well, identify weaknesses in the response, and update the incident response plan. In which phase of the incident handling process does this activity occur?
- Post-Incident Activity (Lessons Learned) (Correct answer)
- Recovery
- Preparation
- Containment
Correct answer: Post-Incident Activity (Lessons Learned)
The Post-Incident Activity, or Lessons Learned, phase is a critical final step where the team analyzes the incident and the response to it. The goal is to improve security controls and the incident handling process itself to prevent or better handle future incidents.
Question 6: According to the NIST SP 800-61 incident response lifecycle, what is the correct sequence of the major phases?
- Detection, Containment, Preparation, Recovery
- Identification, Eradication, Recovery, Preparation
- Preparation, Detection and Analysis, Containment/Eradication/Recovery, Post-Incident Activity (Correct answer)
- Containment, Preparation, Detection, Post-Incident Activity
Correct answer: Preparation, Detection and Analysis, Containment/Eradication/Recovery, Post-Incident Activity
The widely adopted NIST incident response lifecycle follows a logical progression: first, you prepare for incidents; then you detect and analyze them; next, you contain, eradicate, and recover from them; and finally, you conduct post-incident activities to learn from the event.
Which of the following activities is a critical component of the 'Preparation' phase of the security incident handling process, according to the NIST framework?