CSC Incident Response and Reporting 2 — Questions and Answers
Question 1: During the containment phase of incident response, which action should be taken FIRST?
- Eradicate all malware from affected systems
- Isolate affected systems to prevent lateral movement (Correct answer)
- Notify law enforcement about the breach
- Conduct a full forensic investigation
Correct answer: Isolate affected systems to prevent lateral movement
Isolating affected systems during containment prevents the threat from spreading to other network segments before remediation begins.
Question 2: Which regulation requires covered entities to report a breach of unsecured protected health information within 60 days of discovery?
- PCI DSS
- GDPR
- HIPAA Breach Notification Rule (Correct answer)
- SOX
Correct answer: HIPAA Breach Notification Rule
The HIPAA Breach Notification Rule mandates that covered entities notify affected individuals, HHS, and sometimes media within 60 days of discovering a breach.
Question 3: A 'chain of custody' document in incident response primarily ensures:
- That incident costs are tracked for insurance claims
- That evidence integrity is maintained for potential legal proceedings (Correct answer)
- That all stakeholders are notified in the correct order
- That system backups are created before remediation
Correct answer: That evidence integrity is maintained for potential legal proceedings
Chain of custody documentation tracks who handled digital evidence and when, preserving its admissibility in legal or regulatory proceedings.
Question 4: Under GDPR, what is the maximum timeframe for reporting a personal data breach to the relevant supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires controllers to notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it.
Question 5: Which document defines the roles, responsibilities, and communication procedures to follow during a cybersecurity incident?
- Business Continuity Plan (BCP)
- Incident Response Plan (IRP) (Correct answer)
- Disaster Recovery Plan (DRP)
- Vulnerability Management Policy
Correct answer: Incident Response Plan (IRP)
The Incident Response Plan outlines procedures, assigns roles, and establishes communication flows specifically for managing cybersecurity incidents.
Question 6: After fully remediating an incident, what is the purpose of conducting a 'lessons learned' session?
- To assign blame to responsible individuals
- To document the incident for insurance purposes only
- To identify gaps and improve future incident response capabilities (Correct answer)
- To satisfy audit requirements without operational value
Correct answer: To identify gaps and improve future incident response capabilities
Lessons learned sessions capture what went well and what failed so the organization can strengthen detection, response, and prevention for future incidents.
Question 7: Which NIST CSF function most directly encompasses incident response activities?
- Identify
- Protect
- Respond (Correct answer)
- Recover
Correct answer: Respond
The NIST CSF 'Respond' function covers activities including response planning, communications, analysis, mitigation, and improvements during an incident.
During the containment phase of incident response, which action should be taken FIRST?