Incident Response & Recovery Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Incident Response & Recovery flashcards as text
Which NIST publication provides guidance specifically on Contingency Planning for Federal Information Systems?
Answer: NIST SP 800-34
NIST SP 800-34 (Contingency Planning Guide for Federal Information Systems) provides guidance on developing contingency plans for IT systems.
An organization's systems are partially restored after a ransomware attack, but a decision must be made about declaring the incident closed. Who has the authority to make this declaration?
Answer: The designated Authorizing Official or senior management, not the technical team
Declaring an incident closed is a management decision, typically made by senior leadership or the AO, not solely by technical staff.
What is the primary risk of using a compromised system's live memory (RAM) image as forensic evidence without proper precautions?
Answer: Volatile memory is overwritten when the system is powered off or processes change
RAM is volatile — its contents change constantly and are lost at power-off, so forensic capture must be performed quickly with tools that minimize system disruption.
During incident eradication, a technician reimages a compromised server. What critical step must occur BEFORE reimaging to support potential legal action?
Answer: Obtain a forensic image of the original disk
A forensic image of the original disk must be taken before reimaging to preserve evidence that may be needed for legal proceedings or deeper analysis.
In the context of CAP and ATO management, how does a security incident directly affect an existing Authorization to Operate?
Answer: A significant incident may trigger a requirement to reassess or revoke the ATO
A significant security incident that changes the risk posture of a system may require the Authorizing Official to reassess, modify conditions of, or revoke the existing ATO.
Which metric best measures the effectiveness of an incident response team's detection capabilities?
Answer: Mean Time to Detect (MTTD)
Mean Time to Detect (MTTD) measures how long it takes to identify a security incident after it begins, directly reflecting detection capability effectiveness.
A federal agency's Incident Response Plan requires testing. Which test type provides the MOST realistic assessment of the plan's effectiveness?
Answer: Full-scale simulation exercise
A full-scale simulation exercise activates actual response procedures and personnel, providing the most realistic test of both the plan and the team's execution capability.