Incident Response and Reporting Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response and Reporting flashcards as text
An incident response report must include a 'scope of work' section. What is the PRIMARY purpose of this section?
Answer: To define the boundaries of the investigation, including systems examined and time periods covered
The scope of work clearly defines what was examined and what was excluded, ensuring readers understand the limitations and coverage of the forensic investigation.
During triage of a security incident, a CFE must prioritize which systems to examine first. Which factor should carry the MOST weight in this decision?
Answer: The criticality of the system to business operations and its role in the incident
Systems that are critical to operations and most likely to contain relevant evidence or be vectors for ongoing attack should be prioritized during triage.
A forensic examiner's report states that malware was 'possibly' installed on the target system. From a legal and evidentiary standpoint, this language indicates:
Answer: The finding does not meet the examiner's threshold of certainty and reflects uncertainty in the conclusion
Qualified language such as 'possibly' or 'likely' in forensic reports signals that the examiner lacks sufficient evidence to state the conclusion with certainty, which matters to attorneys and courts.
Which of the following BEST describes the role of a 'first responder' in a digital forensics incident?
Answer: The first trained individual to secure the scene, preserve volatile evidence, and document the initial state
A digital first responder is responsible for securing the environment, capturing volatile evidence, and documenting conditions before any changes occur to the scene.
When an organization experiences a data breach involving personally identifiable information (PII), the incident response report should include:
Answer: The number and type of records affected, applicable notification obligations, and regulatory implications
PII breaches trigger regulatory notification requirements, so reports must document the scope of affected records and the applicable legal obligations such as HIPAA, GDPR, or state breach laws.
A CFE is reviewing an incident where an attacker moved laterally through the network using stolen credentials. Which log source would BEST help trace this lateral movement?
Answer: Active Directory authentication logs and Windows Security Event Log (Event ID 4624/4625)
Active Directory and Windows Security Event Logs record successful and failed logon attempts, making them the primary source for tracing lateral movement via credential reuse.
An incident response team completes remediation but fails to identify the initial attack vector. What is the PRIMARY risk of this oversight?
Answer: The attacker may exploit the same vulnerability again, leading to reinfection
Failing to identify and close the initial attack vector leaves the organization vulnerable to re-exploitation through the same entry point, potentially causing recurring incidents.