← All CCP Flashcard Decks

Incident Response & Threat Management Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Incident Response & Threat Management flashcards as text
  1. In the MITRE ATT&CK framework, which tactic describes an adversary's actions to maintain access after initial compromise?

    Answer: Persistence

    The Persistence tactic covers techniques like scheduled tasks, registry run keys, and backdoors that allow attackers to survive reboots or credential changes.

  2. A security team is performing lessons learned after a breach. Which output is MOST valuable for improving future IR capability?

    Answer: Updated playbooks reflecting gaps identified during the response

    Updated playbooks directly improve future response speed and consistency by codifying what worked and fixing what failed during the incident.

  3. Which containment strategy is BEST suited for a targeted APT intrusion where stealth and intelligence gathering are priorities?

    Answer: Soft containment — monitor attacker activity while limiting spread

    Soft containment allows defenders to observe adversary TTPs and collect intelligence while preventing lateral movement, which is valuable against sophisticated threat actors.

  4. What does a high ratio of failed-to-successful login attempts on a single account over a short period MOST likely indicate?

    Answer: Brute-force or credential stuffing attack

    Many failed attempts followed by a success on one account is the classic signature of brute-force or credential stuffing rather than a distributed spray.

  5. During forensic analysis of a compromised Linux server, which artifact would BEST reveal recently executed commands by the attacker?

    Answer: ~/.bash_history for the compromised user account

    The .bash_history file records commands executed in the bash shell for the specific user, providing a direct log of attacker activity if not cleared.

  6. An IR team confirms data exfiltration occurred. Under GDPR, what is the maximum notification window to the supervisory authority after becoming aware of the breach?

    Answer: 72 hours

    GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, unless it is unlikely to result in risk.

  7. Which tool category is MOST appropriate for correlating events across multiple log sources to detect multi-stage attacks?

    Answer: SIEM (Security Information and Event Management)

    A SIEM aggregates and correlates log data from diverse sources, enabling detection of attack patterns that span multiple systems and time windows.