Incident Response & Recovery Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response & Recovery flashcards as text
Which role within an incident response team is responsible for coordinating communications with external parties such as law enforcement and the media?
Answer: Public Affairs Officer / Liaison
The Public Affairs Officer or Liaison manages external communications including media, law enforcement, and other stakeholders during an incident.
Under FISMA, an agency experiences a breach of PII affecting 5,000 individuals. What additional reporting requirement is triggered?
Answer: Notify affected individuals and potentially US-CERT within strict timelines
Breaches of PII trigger mandatory notification to affected individuals and US-CERT reporting under OMB guidelines and agency privacy policies.
What is the purpose of a 'jump bag' in incident response?
Answer: A portable kit of tools and documentation ready for immediate incident response deployment
A jump bag is a pre-packed collection of hardware, software, and documentation that responders can grab immediately when deploying to handle an incident.
During post-incident analysis, a team discovers the attack exploited an unpatched vulnerability. According to NIST SP 800-61, this finding should primarily feed into:
Answer: The lessons learned report and remediation plan
Post-incident analysis findings, especially root cause identification, should be documented in the lessons learned report and drive concrete remediation actions.
Which type of incident response team model is most appropriate for a large federal agency with geographically dispersed offices?
Answer: Distributed team
A distributed team model places incident handlers at multiple geographic locations, making it better suited for large agencies with dispersed operations.
In Business Continuity Planning (BCP), what distinguishes a Recovery Time Objective (RTO) from a Recovery Point Objective (RPO)?
Answer: RTO is the maximum acceptable downtime; RPO is the maximum acceptable data loss
RTO defines how quickly systems must be restored after disruption, while RPO defines how much data loss (measured in time) is acceptable.
A CAP professional is reviewing an Incident Response Plan (IRP). Which element is MOST critical to verify is current and accurate?
Answer: Contact information for the incident response team and escalation paths
Outdated contact information and escalation paths are among the most common reasons IRPs fail during actual incidents, making this the most critical element to keep current.