Font size
WorksheetsIncident Response Policy 2
Total questions: 10
Worksheet time: 7mins
Why do we need to protect evidence of an incident?
In case we want to prosecute the attacker.
So we can use it as a reference for future attacks
For use in training new CSIRT members.
We shouldn't protect it. All evidence should be deleted asap.
How many backups of our evidence should we take?
0
1
2
3
We should remove and securely store the original hard disks and keep them for the purpose of forensic analysis during any prosecution.
True
False
Which of the following are external agencies we might wish to notify of an incident?
Law enforcement agencies
Senior management
External security & virus experts
Legal representatives
When recovering the system you should only restore from backups less than a week old.
True
False
When compiling evidence who should sign off on the documentation? (Select 2)
Management
Law enforcement agencies
Legal representatives
The CSIRT incident lead
Why do we compile and organize our evidence?
To make it easier to backup.
As evidence for prosecution of the attacker.
To help restore the system from the effects of the attack.
To help update our policies and improve training.
When compiling incident evidence, the documentation should clearly show what?
Description of the incident itself
Phone number of all managers
Description of the organisation
Description of the ICT department
The two backups of for the evidence will be required for _______ and _____________
Archiving
Evidence
Data recovery
ICT department
What word is used to describe the process of collecting, identifying, preserving and examining of evidence during an investigation?
Gathering
Forensic Analysis
Finding problems
Disaster recovery
