โ† All CCISO Flashcard Decks

Incident Management & Response Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Management & Response flashcards as text
  1. During a major security incident, the CEO asks the CISO for a real-time status update every 30 minutes. What is the BEST way to handle this without compromising the IR team's effectiveness?

    Answer: Designate a communications liaison to provide structured executive briefings on a defined schedule while the IR team focuses on response

    A designated communications liaison allows executive stakeholders to receive regular updates without disrupting the IR team's focus on containment and investigation activities.

  2. Which NIST SP 800-61 phase involves activities such as reimaging systems, changing all compromised credentials, and patching exploited vulnerabilities?

    Answer: Eradication

    The Eradication phase focuses on removing the threat from the environment by reimaging, patching, and eliminating all attacker footholds before recovery begins.

  3. A CISO is building metrics to demonstrate IR program maturity to the board. Which combination of metrics BEST conveys both efficiency and effectiveness of the IR program?

    Answer: MTTD, MTTC, MTTR, and incident recurrence rate

    MTTD, MTTC, MTTR, and recurrence rate together measure how quickly threats are found, stopped, recovered from, and whether root causes are addressed, providing a complete maturity picture.

  4. An IR investigation reveals that attackers pivoted from a compromised workstation to a domain controller using pass-the-hash. Which remediation strategy MOST directly addresses the technique used?

    Answer: Implementing Credential Guard and restricting NTLM authentication to reduce hash extraction and reuse

    Credential Guard protects NTLM hashes from extraction from memory, and restricting NTLM directly reduces the attack surface for pass-the-hash lateral movement.

  5. A CISO implements a 'purple team' program as a continuous improvement mechanism for incident response. What distinguishes this from a traditional red team engagement?

    Answer: Purple teams involve real-time collaboration between offensive and defensive teams to improve detection and response in place, rather than a blind adversarial test

    Purple teaming emphasizes continuous knowledge transfer and joint improvement between red and blue teams, whereas traditional red teams operate independently to test without bias.

  6. Which of the following scenarios would MOST likely trigger a legal hold that affects how an IR team handles forensic evidence?

    Answer: Anticipated or active litigation, regulatory investigation, or law enforcement involvement related to the incident

    Legal holds are triggered when litigation, regulatory investigations, or law enforcement involvement is reasonably anticipated, requiring evidence to be preserved in an unaltered state.

  7. A CISO is responsible for ensuring that incident response capabilities scale appropriately as the organization grows. Which approach BEST supports scalable IR capability over time?

    Answer: Implementing a tiered response model with defined escalation paths, regularly updated playbooks, and integration of automation for high-volume, low-complexity incidents

    A tiered model with escalation paths, living playbooks, and automation handles increasing incident volume efficiently while preserving human judgment for complex events.