Incident Response and Reporting Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response and Reporting flashcards as text
During an incident response engagement, a forensic examiner discovers that volatile memory contains evidence of a running malware process. What is the MOST appropriate first action?
Answer: Capture a memory dump before taking any other action
Volatile memory (RAM) is lost when a system is powered off, so capturing a memory dump must be prioritized before any other action that could destroy this evidence.
A CFE is asked to document the chain of custody for digital evidence collected during an incident. Which element is NOT typically required in a chain of custody log?
Answer: The monetary value of the evidence
Chain of custody logs document who handled evidence and when, but the monetary value of the item is not a standard chain of custody requirement.
When preparing an incident response report for a non-technical executive audience, which approach is MOST appropriate?
Answer: Focus on business impact, risk exposure, and remediation recommendations in plain language
Executive reports should translate technical findings into business impact and actionable recommendations that non-technical stakeholders can understand and act upon.
An organization suspects an insider threat has been exfiltrating data. During incident response, which log source would MOST directly evidence data exfiltration activity?
Answer: Data Loss Prevention (DLP) system logs and proxy logs showing large outbound transfers
DLP and proxy logs capture outbound data transfers and can reveal unauthorized exfiltration of sensitive data by insiders.
In an incident response timeline, the 'dwell time' refers to:
Answer: The period between initial compromise and detection of a breach
Dwell time is the period an attacker remains undetected in a network between initial compromise and discovery, and shorter dwell times reduce breach impact.
A forensic examiner finds that system logs on a compromised server have been deleted. What technique can BEST help recover information about the attacker's activities?
Answer: Examining network flow data, firewall logs, and SIEM records from external sources
When local logs are deleted, external data sources such as network flows, firewall logs, and SIEM records that collected logs before deletion become critical alternate evidence.
Which of the following BEST describes the purpose of a 'lessons learned' session after an incident response engagement?
Answer: To identify what worked, what failed, and how to improve future response capabilities
Lessons learned sessions are process improvement exercises that help organizations strengthen their security posture and response procedures based on actual incident experience.