← All CSC Flashcard Decks

Crisis Management & Incident Response Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Crisis Management & Incident Response flashcards as text
  1. A security consultant is helping a client define their Recovery Time Objective (RTO). What does RTO specifically measure?

    Answer: Maximum acceptable downtime before business operations must be restored

    RTO defines the maximum acceptable duration that a system or process can be offline before the impact becomes unacceptable to the business.

  2. Which type of attack requires the MOST immediate crisis response due to its potential to permanently destroy data or disable systems at scale?

    Answer: Wiper malware deployment across enterprise systems

    Wiper malware is designed to permanently destroy data and disable systems, making rapid containment critical to prevent irreversible damage.

  3. During incident response, when is it appropriate to involve outside legal counsel?

    Answer: As early as possible to ensure attorney-client privilege protects the investigation

    Involving legal counsel early establishes attorney-client privilege, which can protect investigation findings and communications from discovery in potential litigation.

  4. What is a 'purple team' exercise in the context of incident response preparation?

    Answer: A joint exercise where red team attackers and blue team defenders collaborate to improve detection and response

    Purple team exercises combine red team offensive techniques with blue team defensive monitoring in a collaborative setting to identify gaps in detection and response.

  5. Which artifact is MOST valuable when reconstructing the timeline of a Linux system compromise during forensic analysis?

    Answer: System and authentication logs from /var/log/

    Linux system and authentication logs in /var/log/ (such as auth.log and syslog) provide timestamped records of logins, sudo usage, and system events critical to timeline reconstruction.

  6. An organization's incident response plan assigns a specific individual to make final decisions during a crisis. What is this role typically called?

    Answer: Incident Commander

    The Incident Commander is the designated authority responsible for overall decision-making and coordination during an active incident or crisis response.

  7. What is the MAIN risk of conducting eradication steps too quickly during incident response?

    Answer: Destroying forensic evidence needed to understand the attack and prevent recurrence

    Rushing eradication before completing forensic collection can destroy evidence needed to identify root cause, attack vectors, and scope of compromise.