Incident Response & Threat Management Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response & Threat Management flashcards as text
Which memory forensics artifact would MOST reliably reveal an injected shellcode payload that never touched disk?
Answer: Volatile memory dump analyzed for injected executable regions
Fileless malware exists only in memory; a RAM dump analyzed with tools like Volatility can reveal injected code in process address spaces that leave no disk artifacts.
A threat hunter identifies C2 beacon traffic with a jittered 5-minute callback interval. What is the PRIMARY reason adversaries add jitter to beacon intervals?
Answer: To evade detection by behavioral analytics that flag regular periodic connections
Jitter randomizes callback timing so the traffic pattern does not match the perfectly regular intervals that anomaly detection systems flag as beaconing.
During an IR, the legal team requests a litigation hold. What is the IR team's IMMEDIATE obligation?
Answer: Suspend normal log rotation and preserve all relevant data indefinitely until released
A litigation hold requires freezing evidence destruction processes and preserving all potentially relevant records to avoid spoliation claims.
Which indicator would BEST distinguish a sophisticated APT from opportunistic commodity malware during initial triage?
Answer: Attackers use custom tooling, live-off-the-land binaries, and target-specific reconnaissance
APTs typically use bespoke tools, legitimate system utilities (LOLBins), and demonstrate pre-attack target research, distinguishing them from mass-distributed commodity threats.
An organization wants to measure how quickly it identifies a breach after it occurs. Which metric directly reflects this capability?
Answer: Mean Time to Detect (MTTD)
Mean Time to Detect (MTTD) measures the average elapsed time between when an intrusion begins and when the security team first identifies it.
Which technique allows an attacker to execute malicious code within the address space of a legitimate Windows process to avoid detection?
Answer: Process Injection
Process injection (e.g., DLL injection, process hollowing) loads attacker code into a trusted process so malicious activity appears to originate from a legitimate application.
When performing root cause analysis after an incident, the '5 Whys' methodology is BEST used to:
Answer: Trace a symptom back to its underlying systemic failure
The 5 Whys iteratively drills down from the observable symptom to the root systemic cause, enabling fixes that prevent recurrence rather than just treating symptoms.