wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Incident Response Policy 2

Total questions: 10

Worksheet time: 7mins

Name
Class
Date
1.

Why do we need to protect evidence of an incident?

a)

In case we want to prosecute the attacker.

b)

So we can use it as a reference for future attacks

c)

For use in training new CSIRT members.

d)

We shouldn't protect it. All evidence should be deleted asap.

2.

How many backups of our evidence should we take?

a)

0

b)

1

c)

2

d)

3

3.

We should remove and securely store the original hard disks and keep them for the purpose of forensic analysis during any prosecution.

a)

True

b)

False

4.

Which of the following are external agencies we might wish to notify of an incident?

a)

Law enforcement agencies

b)

Senior management

c)

External security & virus experts

d)

Legal representatives

5.

When recovering the system you should only restore from backups less than a week old.

a)

True

b)

False

6.

When compiling evidence who should sign off on the documentation? (Select 2)

a)

Management

b)

Law enforcement agencies

c)

Legal representatives

d)

The CSIRT incident lead

7.

Why do we compile and organize our evidence?

a)

To make it easier to backup.

b)

As evidence for prosecution of the attacker.

c)

To help restore the system from the effects of the attack.

d)

To help update our policies and improve training.

8.

When compiling incident evidence, the documentation should clearly show what?

a)

Description of the incident itself

b)

Phone number of all managers

c)

Description of the organisation

d)

Description of the ICT department

9.

The two backups of for the evidence will be required for _______ and _____________

a)

Archiving

b)

Evidence

c)

Data recovery

d)

ICT department

10.

What word is used to describe the process of collecting, identifying, preserving and examining of evidence during an investigation?

a)

Gathering

b)

Forensic Analysis

c)

Finding problems

d)

Disaster recovery