← All CCP Flashcard Decks

Incident Response & Threat Management Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Incident Response & Threat Management flashcards as text
  1. During a ransomware incident, the IR team isolates affected hosts but discovers the malware has a kill-switch domain. What is the BEST immediate action?

    Answer: Sinkhole the kill-switch domain to prevent detonation

    Sinkholing the kill-switch domain redirects C2 traffic to a controlled server, potentially halting further encryption while preserving forensic evidence.

  2. Which NIST SP 800-61 phase involves capturing memory dumps and preserving log files before shutting down compromised systems?

    Answer: Containment, Eradication, and Recovery

    Containment activities include evidence collection such as memory dumps and log preservation before systems are taken offline or reimaged.

  3. A SOC analyst receives an alert that a privileged account logged in from two geographically impossible locations within 10 minutes. This is an example of which threat indicator?

    Answer: Impossible travel anomaly

    Impossible travel anomaly flags authentication events from locations that cannot be physically reached within the observed time window.

  4. What is the primary purpose of a threat intelligence feed in an IR workflow?

    Answer: To enrich IOCs with known adversary TTPs for faster triage

    Threat intelligence feeds provide context such as known malicious IPs, hashes, and TTPs that help analysts quickly assess severity and attribution.

  5. During eradication, an analyst finds a web shell on a public-facing server. After removing it, what is the MOST important follow-up step?

    Answer: Identify and patch the vulnerability that allowed the web shell installation

    Removing the web shell without closing the initial access vector leaves the system vulnerable to immediate re-compromise.

  6. Which triage method prioritizes IR resources by categorizing incidents based on their business impact and scope?

    Answer: Incident severity classification matrix

    A severity classification matrix assigns priority levels (P1–P4) based on criteria like data sensitivity, affected systems count, and regulatory impact.

  7. An attacker uses DNS TXT records to exfiltrate data. Which detection technique is MOST effective against this method?

    Answer: Analyzing DNS query length and frequency anomalies

    DNS exfiltration typically produces unusually long TXT queries or high query frequency that can be detected through behavioral DNS analytics.