Font size
WorksheetsLesson 8.1 Incident Management
Total questions: 40
Worksheet time: 40mins
PICERL is a common Incident Response Framework. It stands for
Planning
Identification
Consult
Erase
Recover
Loop Back
Planning
Identify/Asses
Contain/Intelligence
Evacuate
Recover
Learn
Preparation
Identify/Assess
Contain/Intelligence
Eradication
Recovery
Lessons Learned
What is fundamental to a Incident Response Plan? Check all that apply
Identifying Roles and Responsibilities
Plan Testing and Review
Playbooks
Communication and Notification
(a) exercises are a great way to test your plan through different scenarios.
Training personnel for incidents within the organization, should include:
Response
Reporting
Mitigation
Identification
Having Insurance is a great solution in your Incident Management Plan. It can be leaned on when you don't have the capacity to resolve incidents.
True
False
When is the IR Plan activated?
After every scan that reveals critical vulnerabilities.
As soon as we discover suspicious activity.
When we have a virus.
When we receive a ransom note.
When determining severity of an incident, what two types of impact do we compare?
Formative and Summative
Internal and External
Functional and Informational
Informative and Formative
Both types of impact, Functional and Informative, categorize the level of severity this way.
None
Minor
Moderate
Major
None
Limited
Majority
Non-Recoverable
None
Minor
Moderate
Critical
None
Limited
Moderate
Critical
Once the impact is analyzed, how many levels of severity are there?
1
2
3
4
Information Impact focuses on _______, while Functional Impact focuses on __________.
Notifying, Action
Action, Notifying
Compliance, Expertise
Expertise, Compliance
Severity level 1 is equivalent to which level of impact?
None
Limited
Moderate
Critical
How long should it take for a Level 3 incident be resolved?
2 hours
24 hours
72 hours
Within a week
In order to "stop the bleed" we need to identify patterns of attack. One way of doing this is to identify (a) .
What is an IoC?
Information of Compromise
Information of Concern
Indicator of Compromise
Indicator of Concern
What information does an IoC give us?
Forensic data to help us identify concerns
Informational data that helps identify malicious activity
Informational data to help us identify concerns
Forensic data to identify malicious activity
Where is IoC data typically found? Check all that apply.
System Log Entries
File Hashes
Malicious IP Addresses
Registry Modifications
All of the Above
Which one(s) are examples of TTP's? Check all that apply.
Brute Forcing
Ransomware
BITS Admin Manipulation
Credential Dumping
Command and Control Framework
This is an effective tool that can assist you with more IoC and TTP discovery, which has a very effective APT (Advanced Persistent Threat) profile.
Vulnerability Scanners
MITRE ATT&CK
MDR (Managed Detection and Response)
Packet Sniffer
In order to "stop the bleed" on impacted system, what are some short term strategies? Select all that apply.
Isolate Software
Disable the Account
Disconnect network cables
Reset password
Reset all active logon sessions
In order to "stop the bleed" for compromised Users, what are some short term strategies? Select all that apply.
Disconnect Network Cable
Disable Account
Isolate the network
Change password(s)
Reset logon sessions
During an attack, what can be lost if you shut down the system?
Proprietary Information
Important Data
Evidence
None of the Above
How do you secure all Forensic data? Select all that apply
Take a forensic image of compromised system
Secure volatile logs
Take a memory snapshot of compromised system
Only blue and teal
Only yellow and teal
During the Containment Phase of Incident Management, what the preferred method of isolation?
Network
Software
Hardware
Both blue and teal
What does patient-zero mean?
Don't stop resolving until zero systems are compromised
Identify the initial point of ingress.
People that have Covid but don't appear to have it.
None of the above
During the Eradication Phase, what is the focus?
What some examples of what may take place during the Eradication Phase? Select all that apply.
Account Sanitation
System rebuild and restore
Hardening of system, applications, and network
New Environment Build
Only blue and yellow
Attacks are (a) , so our response must be too!
What is the goal during the Recovery Phase? Select all that apply.
Secure affected assets
Remediate vulnerabilities and deficiencies
Restore systems to operational
Return fully to business
System rebuilds and restores are a significant lift of (a) resources.
When the business is fully operational, after the recover, this indicates the response is complete.
True
False
During the Recovery Phase, how should data be handled?
Determine only if data ex-filtration has occurred
Determine only if data modifications have occurred
Criticality of data ex-filtration and/or modification occurrances, if any
None of the above
What Phase must we continually execute?
Preparation
Identity
Containment
Resolution
Lessons Learned
Upon a compromised attack, with an integrated IR Plan, identify the steps that are likely to occur.
1. Engage insurance
2. Develop a list of IoC
3. Find point of ingress
4. Inform Insurance of findings
5. Wait for their response
1. Determine point of ingress
2. Develop list of IoC
3. Investigate
4. Eradicate attacker
5. Business fully recovered
1. Investigate
2. Develop a complete list of IoC
3. Determine point of ingress
4. Eradicate attacker
5. Business fully recovered.
1. Find point of ingress
2. Develop list of IoC
3. Engage Insurance
4.Eradicate attacker
5. Return to normal operations
Describe what a Playbook is and how it is used.
During what Phase of BEC do these steps reside?
1. Determine members of the CSIRT
2. Determine Extended Members
3. Define escalation paths
4. Ensure email system component logging levels are set.
5. Ensure the logging system is stored in secure locations like a SIEM
Preparation
Identification
Containment
Eradication
Recovery
During what Phase of BEC do these steps reside?
1. Analyze method of compromise evidence will help determine next steps
2. Determine initial method of account compromise
3. Use Indicators of Compromise (IoCs) gathered from previous step to search the environment for other victims
4. Review logs in email system searching for anomalies.
5. Assess victim emails to determine if sensitive information was contained in them
6. Search impacted systems for newly created users or modified user accounts
Preparation
Identification
Containment
Eradication
Recovery
During what Phase of BEC do these steps reside?
1. Reset all passwords associate with identified victims
2. Revoke authentication tokens for all identified victim accounts
3. Inform 3rd Party organizations of any compromise or concerns
4. Block any external organizations identified, during the investigation, and their related domains from sending email to your organization
5. Preserve, anlayze, and isolate malware discovered during the investigation
6. Block all IoCs in email systems and endpoint systems
Preparation
Identification
Containment
Eradication
Recovery
During what phase of BEC do these steps reside?
1. Preserve artifacts, systems, and relevant backups
2. Preserve volatile data
3. Replace or rebuild systems
Preparation
Identification
Consolidation
Eradication
Recovery
During what phase of BEC do these steps reside?
1. Remediate vulnerabilities and gaps
2. Reset passwords for all impacted accounts and/or create replacement accounts and leave the impacted accounts disabled permanently
3. Continue to monitor for malicious activity related to this incident for extended period of time
4. Consult cybersecurity insurance, if needed.
Preparation
Identification
Confinement
Eradication
Recovery
Often, an over-looked phase of mitigating security compromises, where a meeting is called to discuss how things went during the mitigation, and an incident report is distributed is called ___________ _____________.
(a)
