CFE Incident Response and Reporting 1 — Questions and Answers
Question 1: What is the first step in the incident response process?
- Containment
- Eradication
- Preparation (Correct answer)
- Recovery
Correct answer: Preparation
The first step in the incident response process, according to frameworks like NIST, is Preparation. This phase involves establishing policies, procedures, tools, and training for an incident response team *before* an incident occurs. Proper preparation ensures the organization is ready to effectively detect, analyze, contain, and recover from security incidents, minimizing their impact.
Question 2: Why is it important to document each step of incident response?
- To reduce investigation time
- To create incident response playbooks
- To support post-incident reviews
- To provide legal and audit evidence (Correct answer)
Correct answer: To provide legal and audit evidence
Documenting each step of incident response is crucial for creating a detailed record of what happened, when, and what actions were taken. This documentation serves as vital legal and audit evidence, demonstrating due diligence, compliance with regulations, and providing a clear, defensible account of the incident for potential legal proceedings or regulatory reviews. It also supports post-incident reviews for improvement.
Question 3: Which phase of incident response involves eliminating the root cause of an incident?
- Identification
- Containment
- Recovery
- Eradication (Correct answer)
Correct answer: Eradication
The Eradication phase of incident response focuses on eliminating the root cause of the incident, such as removing malware, patching vulnerabilities, or disabling compromised user accounts. This step ensures that the threat is completely removed from the affected systems and prevents re-infection or recurrence of the incident. It's a critical step before systems can be safely restored.
Question 4: What is the purpose of containment during an incident?
- To delete infected files
- To notify stakeholders
- To stop the attacker permanently
- To isolate affected systems (Correct answer)
Correct answer: To isolate affected systems
Containment is the phase of incident response aimed at limiting the scope and impact of a security incident by isolating affected systems or networks. The primary purpose is to prevent further damage, stop the spread of an attack, and minimize the overall business disruption while preparing for eradication and recovery. This might involve disconnecting systems or implementing firewall rules.
Question 5: What should be included in an incident report?
- Only the list of affected users
- High-level summary of the incident
- Details of the attack only
- Timeline, actions taken, and recommendations (Correct answer)
Correct answer: Timeline, actions taken, and recommendations
A comprehensive incident report should include a detailed timeline of events, a clear description of all actions taken during the response, and specific recommendations for preventing similar incidents in the future. This provides a complete picture of the incident, the response efforts, and lessons learned for organizational improvement. It serves as a vital communication and documentation tool.
Question 6: Why is post-incident review critical in the response process?
- To punish those responsible
- To close the investigation quickly
- To improve future incident handling (Correct answer)
- To delete logs and reports
Correct answer: To improve future incident handling
A post-incident review, also known as a 'lessons learned' session, is critical for evaluating the effectiveness of the incident response process. It helps identify what went well, what could be improved, and what changes are needed in policies, procedures, or tools to enhance the organization's ability to handle future security incidents more efficiently and effectively. This continuous improvement cycle strengthens overall security posture.
What is the first step in the incident response process?