โ† All CSC Flashcard Decks

Audit, Monitoring & Incident Response Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Audit, Monitoring & Incident Response flashcards as text
  1. Which log retention period is typically required by PCI DSS for audit logs?

    Answer: 90 days online, 1 year archived

    PCI DSS requires audit logs to be retained for at least 12 months, with the most recent 3 months immediately available for analysis.

  2. A SIEM alert fires on 500 events per hour but the SOC analyst finds most are false positives. What is the BEST corrective action?

    Answer: Tune the detection rule with additional context filters

    Tuning detection rules with additional context filters reduces false positives while preserving detection of genuine threats.

  3. During an incident, the IR team needs to preserve volatile memory evidence. Which action should be performed FIRST?

    Answer: Capture a live memory dump before any other action

    Volatile memory is lost on power-off, so capturing a live memory dump must occur before other evidence collection or shutdown.

  4. What is the PRIMARY purpose of a lessons-learned meeting after a security incident?

    Answer: Identify process gaps and improve future response

    Lessons-learned meetings focus on identifying gaps in detection, response, and controls to continuously improve the incident response process.

  5. Which metric BEST measures the effectiveness of an incident response program over time?

    Answer: Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)

    MTTD and MTTR directly measure how quickly threats are identified and contained, reflecting IR program maturity.

  6. An auditor requests evidence that privileged user activity is being monitored. Which control BEST satisfies this requirement?

    Answer: Implementing a Privileged Access Management (PAM) solution with session recording

    PAM solutions with session recording provide direct evidence of privileged activity monitoring, including command logs and video playback.

  7. Which incident classification category describes an event where sensitive data has been confirmed as accessed by an unauthorized party?

    Answer: Data breach

    A data breach specifically involves confirmed unauthorized access to sensitive data, distinguishing it from a general security incident.