Incident Response & Recovery Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response & Recovery flashcards as text
Which NIST SP 800-61 phase involves preserving evidence and limiting the scope of a security incident?
Answer: Containment, Eradication, and Recovery
The Containment, Eradication, and Recovery phase focuses on stopping the spread of an incident and preserving evidence while restoring systems.
During incident response, what is the primary purpose of a chain of custody document?
Answer: To ensure evidence integrity and admissibility
Chain of custody documents track who handled evidence and when, ensuring its integrity and legal admissibility.
A security analyst notices anomalous outbound traffic to an unknown IP address. According to NIST SP 800-61, this falls into which incident category?
Answer: Malicious Code
Anomalous outbound traffic to unknown IPs is typically indicative of malicious code (e.g., malware beaconing to a C2 server).
In the context of FedRAMP incident reporting, what is the required timeframe for reporting a major incident to US-CERT?
Answer: Within 1 hour
FedRAMP requires cloud service providers to report major security incidents to US-CERT within one hour of discovery.
What is the key difference between a security 'event' and a security 'incident' under NIST SP 800-61?
Answer: An incident adversely affects information or systems, while an event is any observable occurrence
An event is any observable occurrence in a system, while an incident is an event that actually or potentially jeopardizes confidentiality, integrity, or availability.
Which containment strategy involves isolating a compromised system while keeping it running to gather additional intelligence?
Answer: Long-term containment
Long-term containment allows a compromised system to remain operational in isolation so analysts can observe attacker behavior and gather intelligence.
After eradicating a threat and restoring systems, which activity is critical before returning systems to full production?
Answer: Vulnerability scanning and validation testing
Vulnerability scanning and validation testing confirm that the threat has been completely removed and no residual vulnerabilities remain before systems go back into production.