Incident Response and Forensics Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response and Forensics flashcards as text
A post-incident review is conducted after every major security incident. What is the primary goal of this activity?
Answer: To identify lessons learned and improve future response capabilities
Post-incident reviews (lessons learned sessions) are conducted to identify what worked, what didn't, and how processes and controls can be improved to prevent or better handle future incidents.
Which type of evidence is derived from a primary source and may be used to support other evidence in a forensic investigation?
Answer: Corroborative evidence
Corroborative evidence supports or confirms other evidence in the case; it does not stand alone but strengthens the overall body of evidence.
During eradication of an incident, a responder removes malware from all affected systems. What should immediately follow eradication before returning systems to production?
Answer: Performing recovery and verification
After eradication, recovery involves restoring systems to normal operation and verifying they are clean and functioning correctly before returning them to the production environment.
What is the role of an incident response retainer agreement with a third-party IR firm?
Answer: It ensures access to specialized IR expertise on short notice when needed
A retainer agreement with an external IR firm provides pre-negotiated access to specialized expertise and resources that can be quickly engaged when the organization needs help responding to a significant incident.
Which memory forensics artifact can reveal currently running processes, open network connections, and loaded drivers that may not appear in on-disk analysis?
Answer: RAM (volatile memory) dump
A RAM dump captures volatile memory that contains live process information, network connections, encryption keys, and loaded drivers, revealing attacker activity that may not persist on disk.
Which term describes an attack technique where an adversary uses legitimate administrative tools (e.g., PowerShell, WMI) to conduct malicious activity, making detection harder?
Answer: Living off the land (LotL)
Living off the land (LotL) attacks use built-in OS tools and legitimate software to carry out malicious activities, blending in with normal administrative behavior and evading signature-based detection.
Under the NIST incident response lifecycle, which phase directly follows containment, eradication, and recovery?
Answer: Post-Incident Activity
The NIST IR lifecycle ends with Post-Incident Activity (lessons learned), which follows the Containment, Eradication, and Recovery phase to improve future response capabilities.