โ† All CCISO Flashcard Decks

Incident Management & Response Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Management & Response flashcards as text
  1. A CISO learns that an attacker exfiltrated 500GB of sensitive data before the intrusion was detected. Which gap in the incident response program most directly contributed to this outcome?

    Answer: Insufficient data loss prevention and egress monitoring controls

    Insufficient egress monitoring and DLP controls allow large-scale data exfiltration to go undetected, directly enabling prolonged data loss.

  2. During post-incident analysis, the IR team determines that the mean time to detect (MTTD) was 47 days. As CISO, which metric should you prioritize improving first to reduce business impact from future incidents?

    Answer: Mean time to detect (MTTD)

    Reducing MTTD shortens the window attackers have to cause damage, directly reducing overall business impact before containment can even begin.

  3. A ransomware attack has encrypted critical operational systems. The IR team recommends paying the ransom to restore operations quickly. What should the CISO do FIRST?

    Answer: Consult legal counsel and law enforcement before authorizing payment

    Legal counsel must assess sanctions exposure and regulatory obligations, and law enforcement engagement may be legally required before any ransom payment is made.

  4. Which forensic principle ensures that evidence collected during an incident investigation is admissible in legal proceedings?

    Answer: Chain of custody documentation

    Chain of custody documents who handled evidence, when, and how, ensuring its integrity and admissibility in court.

  5. An IR team discovers that an attacker maintained persistence via a scheduled task that survived reimaging because it was stored on a network share. This illustrates which concept?

    Answer: Persistent foothold via off-system storage

    Storing persistence mechanisms on network shares rather than local disk allows them to survive endpoint reimaging, a technique CISOs must account for in remediation plans.

  6. A CISO is designing a tiered incident severity classification scheme. Which criterion is MOST important when assigning the highest severity tier?

    Answer: Potential impact on business-critical operations, regulatory obligations, or reputational damage

    Severity classification must be anchored to business impact, regulatory exposure, and reputational risk, not merely technical indicators or source of attack.

  7. During an active intrusion, an IR analyst recommends immediately blocking all outbound traffic to stop exfiltration. The CISO must weigh this against which competing concern?

    Answer: Risk of alerting the attacker before evidence is collected

    Premature containment actions can alert attackers to change tactics or destroy evidence before forensic collection is complete, undermining the investigation.