Incident Response Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Incident Response flashcards as text
During the containment phase of incident response, a security analyst isolates an infected workstation from the network. Which action should be taken NEXT?
Answer: Preserve forensic evidence before any remediation
Preserving forensic evidence before remediation ensures that volatile data and artifacts needed for investigation are not lost.
A CSIRT receives an alert that a user's credentials were used to log in from two geographically distant locations within minutes. What type of indicator is this?
Answer: Behavioral anomaly
Simultaneous logins from impossible geographic locations is a behavioral anomaly that signals credential misuse or account compromise.
Which document formally authorizes a CSIRT to investigate systems and collect evidence during an incident?
Answer: Rules of engagement
Rules of engagement define the scope, authority, and boundaries for CSIRT activities during an investigation.
An analyst discovers ransomware encrypted files on a shared drive. Which containment strategy minimizes business impact while preserving evidence?
Answer: Disable the affected share while keeping systems online
Disabling the specific share prevents further encryption while maintaining system availability for evidence collection and business continuity.
Which metric measures the time from when an incident is detected to when it is fully resolved?
Answer: Mean Time to Respond (MTTR)
Mean Time to Respond (MTTR) measures the total duration from detection through complete resolution of an incident.
After recovering from a data breach, the CSIRT conducts a lessons-learned meeting. What is the PRIMARY purpose of this activity?
Answer: Improve future incident response processes
Lessons-learned meetings are conducted to identify gaps and improve processes, controls, and detection capabilities for future incidents.
A threat actor uses living-off-the-land techniques during an attack. Which detection approach is MOST effective against this method?
Answer: Behavioral analytics and baseline deviation monitoring
Living-off-the-land attacks use legitimate tools, so behavioral analytics detecting deviations from normal usage patterns is the most effective detection method.