Incident Management & Response Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Management & Response flashcards as text
A financial institution experiences a breach affecting 100,000 customer records. Under US regulations, which regulatory body typically requires notification within a specific timeframe for this type of institution?
Answer: Federal banking regulators under the GLBA Safeguards Rule notification requirements
Under the GLBA Safeguards Rule, financial institutions must notify their primary federal banking regulator as soon as possible within 36 hours of discovering a notification event.
Which component of a business continuity plan most directly supports the incident response function during a major cyber event?
Answer: Recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical systems
RTOs and RPOs define acceptable downtime and data loss thresholds, guiding IR prioritization decisions about which systems to restore first.
A CISO wants to test whether the IR team can handle a simulated advanced persistent threat without disrupting production systems. Which exercise type is MOST appropriate?
Answer: Purple team exercise in an isolated lab environment
Purple team exercises in isolated environments allow realistic adversary simulation and IR testing without risking production system availability.
When a security incident involves a third-party cloud provider, the CISO's incident response plan should address which unique challenge?
Answer: Limited direct access to infrastructure and reliance on provider cooperation for evidence collection
In cloud environments, the organization often cannot directly access underlying infrastructure, making evidence collection dependent on the provider's cooperation and contractual SLAs.
An attacker used compromised credentials obtained via credential stuffing to access a customer portal. After containment, which remediation action has the highest long-term impact on preventing recurrence?
Answer: Implementing multi-factor authentication across all customer-facing portals
MFA prevents credential stuffing attacks from succeeding even when valid credentials are obtained, addressing the root cause rather than symptoms.
A CISO reviews the incident response team's post-incident report and notices that root cause analysis was skipped to meet reporting deadlines. What risk does this create?
Answer: Failure to identify systemic vulnerabilities, increasing the likelihood of repeat incidents
Skipping root cause analysis leaves underlying vulnerabilities unaddressed, making the organization susceptible to identical or similar attacks in the future.
In the context of IR communications, what is the primary purpose of a crisis communication plan at the executive level?
Answer: To ensure consistent, accurate, and legally vetted messaging to stakeholders, regulators, and the public during an incident
Executive crisis communication plans coordinate messaging across all stakeholder groups to prevent misinformation, manage reputational damage, and ensure legal compliance during incidents.