wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Lesson 8.1 Incident Management

Total questions: 40

Worksheet time: 40mins

Name
Class
Date
1.

PICERL is a common Incident Response Framework. It stands for

a)

Planning

Identification

Consult

Erase

Recover

Loop Back

b)

Planning

Identify/Asses

Contain/Intelligence

Evacuate

Recover

Learn

c)

Preparation

Identify/Assess

Contain/Intelligence

Eradication

Recovery

Lessons Learned

2.

What is fundamental to a Incident Response Plan? Check all that apply

a)

Identifying Roles and Responsibilities

b)

Plan Testing and Review

c)

Playbooks

d)

Communication and Notification

3.

(a)   exercises are a great way to test your plan through different scenarios.

4.

Training personnel for incidents within the organization, should include:

a)

Response

b)

Reporting

c)

Mitigation

d)

Identification

5.

Having Insurance is a great solution in your Incident Management Plan. It can be leaned on when you don't have the capacity to resolve incidents.

a)

True

b)

False

6.

When is the IR Plan activated?

a)

After every scan that reveals critical vulnerabilities.

b)

As soon as we discover suspicious activity.

c)

When we have a virus.

d)

When we receive a ransom note.

7.

When determining severity of an incident, what two types of impact do we compare?

a)

Formative and Summative

b)

Internal and External

c)

Functional and Informational

d)

Informative and Formative

8.

Both types of impact, Functional and Informative, categorize the level of severity this way.

a)

None

Minor

Moderate

Major

b)

None

Limited

Majority

Non-Recoverable

c)

None

Minor

Moderate

Critical

d)

None

Limited

Moderate

Critical

9.

Once the impact is analyzed, how many levels of severity are there?

a)

1

b)

2

c)

3

d)

4

10.

Information Impact focuses on _______, while Functional Impact focuses on __________.

a)

Notifying, Action

b)

Action, Notifying

c)

Compliance, Expertise

d)

Expertise, Compliance

11.

Severity level 1 is equivalent to which level of impact?

a)

None

b)

Limited

c)

Moderate

d)

Critical

12.

How long should it take for a Level 3 incident be resolved?

a)

2 hours

b)

24 hours

c)

72 hours

d)

Within a week

13.

In order to "stop the bleed" we need to identify patterns of attack. One way of doing this is to identify (a)   .

14.

What is an IoC?

a)

Information of Compromise

b)

Information of Concern

c)

Indicator of Compromise

d)

Indicator of Concern

15.

What information does an IoC give us?

a)

Forensic data to help us identify concerns

b)

Informational data that helps identify malicious activity

c)

Informational data to help us identify concerns

d)

Forensic data to identify malicious activity

16.

Where is IoC data typically found? Check all that apply.

a)

System Log Entries

b)

File Hashes

c)

Malicious IP Addresses

d)

Registry Modifications

e)

All of the Above

17.

Which one(s) are examples of TTP's? Check all that apply.

a)

Brute Forcing

b)

Ransomware

c)

BITS Admin Manipulation

d)

Credential Dumping

e)

Command and Control Framework

18.

This is an effective tool that can assist you with more IoC and TTP discovery, which has a very effective APT (Advanced Persistent Threat) profile.

a)

Vulnerability Scanners

b)

MITRE ATT&CK

c)

MDR (Managed Detection and Response)

d)

Packet Sniffer

19.

In order to "stop the bleed" on impacted system, what are some short term strategies? Select all that apply.

a)

Isolate Software

b)

Disable the Account

c)

Disconnect network cables

d)

Reset password

e)

Reset all active logon sessions

20.

In order to "stop the bleed" for compromised Users, what are some short term strategies? Select all that apply.

a)

Disconnect Network Cable

b)

Disable Account

c)

Isolate the network

d)

Change password(s)

e)

Reset logon sessions

21.

During an attack, what can be lost if you shut down the system?

a)

Proprietary Information

b)

Important Data

c)

Evidence

d)

None of the Above

22.

How do you secure all Forensic data? Select all that apply

a)

Take a forensic image of compromised system

b)

Secure volatile logs

c)

Take a memory snapshot of compromised system

d)

Only blue and teal

e)

Only yellow and teal

23.

During the Containment Phase of Incident Management, what the preferred method of isolation?

a)

Network

b)

Software

c)

Hardware

d)

Both blue and teal

24.

What does patient-zero mean?

a)

Don't stop resolving until zero systems are compromised

b)

Identify the initial point of ingress.

c)

People that have Covid but don't appear to have it.

d)

None of the above

25.

During the Eradication Phase, what is the focus?

4 lines
26.

What some examples of what may take place during the Eradication Phase? Select all that apply.

a)

Account Sanitation

b)

System rebuild and restore

c)

Hardening of system, applications, and network

d)

New Environment Build

e)

Only blue and yellow

27.

Attacks are (a)   , so our response must be too!

28.

What is the goal during the Recovery Phase? Select all that apply.

a)

Secure affected assets

b)

Remediate vulnerabilities and deficiencies

c)

Restore systems to operational

d)

Return fully to business

29.

System rebuilds and restores are a significant lift of (a)   resources.

30.

When the business is fully operational, after the recover, this indicates the response is complete.

a)

True

b)

False

31.

During the Recovery Phase, how should data be handled?

a)

Determine only if data ex-filtration has occurred

b)

Determine only if data modifications have occurred

c)

Criticality of data ex-filtration and/or modification occurrances, if any

d)

None of the above

32.

What Phase must we continually execute?

a)

Preparation

b)

Identity

c)

Containment

d)

Resolution

e)

Lessons Learned

33.

Upon a compromised attack, with an integrated IR Plan, identify the steps that are likely to occur.

a)

1. Engage insurance

2. Develop a list of IoC

3. Find point of ingress

4. Inform Insurance of findings

5. Wait for their response

b)

1. Determine point of ingress

2. Develop list of IoC

3. Investigate

4. Eradicate attacker

5. Business fully recovered

c)

1. Investigate

2. Develop a complete list of IoC

3. Determine point of ingress

4. Eradicate attacker

5. Business fully recovered.

d)

1. Find point of ingress

2. Develop list of IoC

3. Engage Insurance

4.Eradicate attacker

5. Return to normal operations

34.

Describe what a Playbook is and how it is used.

4 lines
35.

During what Phase of BEC do these steps reside?

1. Determine members of the CSIRT

2. Determine Extended Members

3. Define escalation paths

4. Ensure email system component logging levels are set.

5. Ensure the logging system is stored in secure locations like a SIEM

a)

Preparation

b)

Identification

c)

Containment

d)

Eradication

e)

Recovery

36.

During what Phase of BEC do these steps reside?

1. Analyze method of compromise evidence will help determine next steps

2. Determine initial method of account compromise

3. Use Indicators of Compromise (IoCs) gathered from previous step to search the environment for other victims

4. Review logs in email system searching for anomalies.

5. Assess victim emails to determine if sensitive information was contained in them

6. Search impacted systems for newly created users or modified user accounts

a)

Preparation

b)

Identification

c)

Containment

d)

Eradication

e)

Recovery

37.

During what Phase of BEC do these steps reside?

1. Reset all passwords associate with identified victims

2. Revoke authentication tokens for all identified victim accounts

3. Inform 3rd Party organizations of any compromise or concerns

4. Block any external organizations identified, during the investigation, and their related domains from sending email to your organization

5. Preserve, anlayze, and isolate malware discovered during the investigation

6. Block all IoCs in email systems and endpoint systems

a)

Preparation

b)

Identification

c)

Containment

d)

Eradication

e)

Recovery

38.

During what phase of BEC do these steps reside?

1. Preserve artifacts, systems, and relevant backups

2. Preserve volatile data

3. Replace or rebuild systems

a)

Preparation

b)

Identification

c)

Consolidation

d)

Eradication

e)

Recovery

39.

During what phase of BEC do these steps reside?

1. Remediate vulnerabilities and gaps

2. Reset passwords for all impacted accounts and/or create replacement accounts and leave the impacted accounts disabled permanently

3. Continue to monitor for malicious activity related to this incident for extended period of time

4. Consult cybersecurity insurance, if needed.

a)

Preparation

b)

Identification

c)

Confinement

d)

Eradication

e)

Recovery

40.

Often, an over-looked phase of mitigating security compromises, where a meeting is called to discuss how things went during the mitigation, and an incident report is distributed is called ___________ _____________.

(a)