โ† All CFE Flashcard Decks

Incident Response and Reporting Flashcards

6 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Incident Response and Reporting flashcards as text
  1. What is the first step in the incident response process?

    Answer: Preparation

    The first step in the incident response process, according to frameworks like NIST, is Preparation. This phase involves establishing policies, procedures, tools, and training for an incident response team *before* an incident occurs. Proper preparation ensures the organization is ready to effectively detect, analyze, contain, and recover from security incidents, minimizing their impact.

  2. Why is it important to document each step of incident response?

    Answer: To provide legal and audit evidence

    Documenting each step of incident response is crucial for creating a detailed record of what happened, when, and what actions were taken. This documentation serves as vital legal and audit evidence, demonstrating due diligence, compliance with regulations, and providing a clear, defensible account of the incident for potential legal proceedings or regulatory reviews. It also supports post-incident reviews for improvement.

  3. Which phase of incident response involves eliminating the root cause of an incident?

    Answer: Eradication

    The Eradication phase of incident response focuses on eliminating the root cause of the incident, such as removing malware, patching vulnerabilities, or disabling compromised user accounts. This step ensures that the threat is completely removed from the affected systems and prevents re-infection or recurrence of the incident. It's a critical step before systems can be safely restored.

  4. What is the purpose of containment during an incident?

    Answer: To isolate affected systems

    Containment is the phase of incident response aimed at limiting the scope and impact of a security incident by isolating affected systems or networks. The primary purpose is to prevent further damage, stop the spread of an attack, and minimize the overall business disruption while preparing for eradication and recovery. This might involve disconnecting systems or implementing firewall rules.

  5. What should be included in an incident report?

    Answer: Timeline, actions taken, and recommendations

    A comprehensive incident report should include a detailed timeline of events, a clear description of all actions taken during the response, and specific recommendations for preventing similar incidents in the future. This provides a complete picture of the incident, the response efforts, and lessons learned for organizational improvement. It serves as a vital communication and documentation tool.

  6. Why is post-incident review critical in the response process?

    Answer: To improve future incident handling

    A post-incident review, also known as a 'lessons learned' session, is critical for evaluating the effectiveness of the incident response process. It helps identify what went well, what could be improved, and what changes are needed in policies, procedures, or tools to enhance the organization's ability to handle future security incidents more efficiently and effectively. This continuous improvement cycle strengthens overall security posture.