โ† All CSC Flashcard Decks

Incident Response and Reporting Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Incident Response and Reporting flashcards as text
  1. During the containment phase of incident response, which action should be taken FIRST?

    Answer: Isolate affected systems to prevent lateral movement

    Isolating affected systems during containment prevents the threat from spreading to other network segments before remediation begins.

  2. Which regulation requires covered entities to report a breach of unsecured protected health information within 60 days of discovery?

    Answer: HIPAA Breach Notification Rule

    The HIPAA Breach Notification Rule mandates that covered entities notify affected individuals, HHS, and sometimes media within 60 days of discovering a breach.

  3. A 'chain of custody' document in incident response primarily ensures:

    Answer: That evidence integrity is maintained for potential legal proceedings

    Chain of custody documentation tracks who handled digital evidence and when, preserving its admissibility in legal or regulatory proceedings.

  4. Under GDPR, what is the maximum timeframe for reporting a personal data breach to the relevant supervisory authority?

    Answer: 72 hours

    GDPR Article 33 requires controllers to notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it.

  5. Which document defines the roles, responsibilities, and communication procedures to follow during a cybersecurity incident?

    Answer: Incident Response Plan (IRP)

    The Incident Response Plan outlines procedures, assigns roles, and establishes communication flows specifically for managing cybersecurity incidents.

  6. After fully remediating an incident, what is the purpose of conducting a 'lessons learned' session?

    Answer: To identify gaps and improve future incident response capabilities

    Lessons learned sessions capture what went well and what failed so the organization can strengthen detection, response, and prevention for future incidents.

  7. Which NIST CSF function most directly encompasses incident response activities?

    Answer: Respond

    The NIST CSF 'Respond' function covers activities including response planning, communications, analysis, mitigation, and improvements during an incident.

Incident Response and Reporting Flashcards โ€” CSC Study Cards with Answers