MSCTC Incident Investigation & Reporting — Questions and Answers
Question 1: In Michigan Sheriffs' Coordinating and Training Council, what is the PRIMARY purpose of network segmentation?
- To limit the spread of security breaches and control access between network zones (Correct answer)
- To increase network speed for all users
- To reduce the cost of network hardware
- To simplify network administration tasks
Correct answer: To limit the spread of security breaches and control access between network zones
Network segmentation limits the lateral movement of attackers and controls access between different network zones, reducing the potential impact of security breaches.
Question 2: Which authentication method provides the STRONGEST security for MSCTC implementations?
- Multi-factor authentication combining something you know, have, and are (Correct answer)
- Single password authentication with complex requirements
- Username-only access with IP restrictions
- Shared credentials across the team
Correct answer: Multi-factor authentication combining something you know, have, and are
Multi-factor authentication (MFA) provides the strongest security by requiring multiple independent verification methods, making unauthorized access significantly more difficult.
Question 3: What is the FIRST step in an incident response process according to Michigan Sheriffs' Coordinating and Training Council best practices?
- Detection and identification of the security incident (Correct answer)
- Immediately shutting down all affected systems
- Notifying law enforcement before investigation
- Erasing logs to prevent further exploitation
Correct answer: Detection and identification of the security incident
The incident response process begins with detection and identification, which involves recognizing that an incident has occurred and determining its scope and nature.
Question 4: In the context of Michigan Sheriffs' Coordinating and Training Council, what does the principle of least privilege mean?
- Users should only have the minimum access rights necessary to perform their job functions (Correct answer)
- All users should have administrator-level access for convenience
- Privileges should be assigned based on seniority
- Access should only be restricted for external contractors
Correct answer: Users should only have the minimum access rights necessary to perform their job functions
The principle of least privilege states that users should only be granted the minimum level of access necessary to perform their job functions, reducing the attack surface.
Question 5: What type of assessment does a MSCTC professional conduct to identify system weaknesses?
- Vulnerability assessment and penetration testing (Correct answer)
- Customer satisfaction surveys
- Financial audits of IT spending
- Employee performance reviews
Correct answer: Vulnerability assessment and penetration testing
Vulnerability assessments and penetration testing are systematic approaches to identifying and evaluating security weaknesses in systems, networks, and applications.
Question 6: Which encryption standard is generally recommended for protecting sensitive data in Michigan Sheriffs' Coordinating and Training Council?
- AES-256 (Advanced Encryption Standard with 256-bit key) (Correct answer)
- DES (Data Encryption Standard)
- ROT13 substitution cipher
- Base64 encoding
Correct answer: AES-256 (Advanced Encryption Standard with 256-bit key)
AES-256 is the current industry standard for encrypting sensitive data, providing strong protection that is approved by government agencies for classified information.
In Michigan Sheriffs' Coordinating and Training Council, what is the PRIMARY purpose of network segmentation?