โ† All CAP Flashcard Decks

Incident Response & Recovery Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response & Recovery flashcards as text
  1. Which NIST SP 800-61 phase involves preserving evidence and limiting the scope of a security incident?

    Answer: Containment, Eradication, and Recovery

    The Containment, Eradication, and Recovery phase focuses on stopping the spread of an incident and preserving evidence while restoring systems.

  2. During incident response, what is the primary purpose of a chain of custody document?

    Answer: To ensure evidence integrity and admissibility

    Chain of custody documents track who handled evidence and when, ensuring its integrity and legal admissibility.

  3. A security analyst notices anomalous outbound traffic to an unknown IP address. According to NIST SP 800-61, this falls into which incident category?

    Answer: Malicious Code

    Anomalous outbound traffic to unknown IPs is typically indicative of malicious code (e.g., malware beaconing to a C2 server).

  4. In the context of FedRAMP incident reporting, what is the required timeframe for reporting a major incident to US-CERT?

    Answer: Within 1 hour

    FedRAMP requires cloud service providers to report major security incidents to US-CERT within one hour of discovery.

  5. What is the key difference between a security 'event' and a security 'incident' under NIST SP 800-61?

    Answer: An incident adversely affects information or systems, while an event is any observable occurrence

    An event is any observable occurrence in a system, while an incident is an event that actually or potentially jeopardizes confidentiality, integrity, or availability.

  6. Which containment strategy involves isolating a compromised system while keeping it running to gather additional intelligence?

    Answer: Long-term containment

    Long-term containment allows a compromised system to remain operational in isolation so analysts can observe attacker behavior and gather intelligence.

  7. After eradicating a threat and restoring systems, which activity is critical before returning systems to full production?

    Answer: Vulnerability scanning and validation testing

    Vulnerability scanning and validation testing confirm that the threat has been completely removed and no residual vulnerabilities remain before systems go back into production.

Incident Response & Recovery Flashcards โ€” CAP Study Cards with Answers