โ† All CAP Flashcard Decks

Incident Response & Recovery Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response & Recovery flashcards as text
  1. Under NIST SP 800-61, what is the recommended first action when an incident is confirmed during the Detection and Analysis phase?

    Answer: Document all findings and prioritize the incident based on impact

    Upon confirming an incident, the handler should document findings and prioritize response efforts based on the incident's functional impact and information impact.

  2. What distinguishes a Disaster Recovery Plan (DRP) from a Business Continuity Plan (BCP)?

    Answer: A DRP covers IT systems only; a BCP addresses the full business operation

    A DRP focuses specifically on recovering IT systems and data, while a BCP addresses maintaining all critical business functions during and after a disruption.

  3. Which indicator type, according to NIST SP 800-61, is considered the MOST reliable for confirming a security incident?

    Answer: Indicators of Compromise (IoCs)

    Indicators of Compromise (IoCs) are direct evidence that an incident has occurred or is in progress, making them the most reliable confirmation of an actual incident.

  4. A system owner wants to minimize data loss in the event of a ransomware attack. Which contingency planning element directly addresses this goal?

    Answer: Backup and restoration strategy aligned with a low RPO

    A backup and restoration strategy designed to meet a low Recovery Point Objective (RPO) directly limits how much data can be lost in the event of an attack.

  5. When conducting a post-incident review, which of the following questions is MOST important for improving the authorization process?

    Answer: Were the security controls in the SSP effective, and should the ATO conditions be updated?

    The CAP professional's primary post-incident concern is whether the security controls and authorization basis remain valid and if the ATO needs to be updated to reflect new risks.

  6. An organization uses a hot site for disaster recovery. What is the PRIMARY advantage of a hot site over a warm site?

    Answer: Hot sites have fully operational systems that allow near-immediate failover

    A hot site is a fully operational duplicate facility with current data that enables near-immediate failover, minimizing downtime compared to a warm site that requires setup time.

  7. Which of the following BEST describes the role of the Security Operations Center (SOC) in the incident response lifecycle?

    Answer: The SOC provides continuous monitoring and serves as the initial detection and triage capability for incidents

    The SOC provides 24/7 monitoring, initial detection, and triage of security events, serving as the front line of the incident response process.