NEW
Font size
WorksheetsModule 19 CSEC
Total questions: 74
Worksheet time: 37mins
What is the primary purpose of Incident Response (IR)?
To create new security policies
To take organized and careful steps when reacting to a security incident
To develop software applications
To train new employees
What is the first step in the sequence of steps involved in Incident Response?
Implementing new security measures
Identifying and reporting an incident
Conducting employee training
Shutting down all systems
How do IR processes vary between organizations?
They are the same for all organizations
They differ according to their business and operating environment
They depend on the size of the organization
They are based on the number of employees
What is the role of the Incident Handling and Response Team?
To develop marketing strategies
To collectively respond, remediate, mitigate, recover, and communicate the impact of incidents involving computer security breaches
To manage financial accounts
To oversee human resources
What does the IH&R team work on when dealing with a security incident?
A marketing plan
An incident response plan
A financial report
A training manual
Who in the IH&R team is responsible for leadership and decision-making authority?
Information Security Team
IT Staff
Management
Attorney
Which role in the IH&R team is tasked with discovering and containing incidents?
Physical Security Staff
Information Security Team
Attorney
IT Staff
Who is responsible for providing legal advice in the IH&R team?
IT Staff
Management
Physical Security Staff
Attorney
Which team member is aware of the information system and network areas?
IT Staff
Attorney
Management
Physical Security Staff
Who is responsible for physical security and identifying the extent of any damage in the IH&R team?
Information Security Team
Physical Security Staff
Management
Attorney
Who is responsible for handling employee issues for an employee involved in an incident?
PR Specialist
Financial Auditor
HR Representative
IR Officer
Which role is responsible for conveying company details after an incident?
IR Manager
PR Specialist
Financial Auditor
IR Custodians
Who assesses the financial loss to a company from an incident?
IR Officer
HR Representative
Financial Auditor
IR Assessment Team
What is the responsibility of the IR Officer?
Handling employee issues
Conveying company details
Leading the IH&R team
Responsible for all actions of the IR Team and IR Function
Who leads the IH&R team in all IR activities?
IR Manager
PR Specialist
Financial Auditor
IR Custodians
What is the role of the IR Assessment Team?
Handling employee issues
Making decisions on classifications and severity of incidents
Conveying company details
Assessing financial loss
Who is responsible for the remediation and resolution of the incident that occurred?
HR Representative
PR Specialist
IR Custodians
Financial Auditor
Who is a first responder?
An individual who arrives first at the crime scene and brings the incident to the attention of others
A person who investigates crimes after they occur
A bystander who witnesses a crime
A police officer who patrols the streets
What role does a first responder play in incident response?
They are responsible for the entire investigation process
They provide great help in early detection of incidents and evidence collection
They only secure the crime scene
They handle all media communications
Which of the following is NOT a responsibility of a first responder?
Familiarity with network traffic and security policy
Conducting the entire forensic investigation
Early detection of incidents
Evidence collection and preservation
What is the first step in the roles and responsibilities of a first responder?
Containing the incident
Reporting the incident
Identifying the crime scene
Documenting all the findings
Which role involves alerting the management and incidence response teams?
Protecting the crime scene
Collecting information
Alerting
Preserving evidence
What does the 'Preserving' role focus on in first responder responsibilities?
Preserving temporary and fragile evidence
Packaging electronic evidence
Containing the incident
Identifying the crime scene
Which responsibility involves packaging and transporting electronic evidence?
Documenting findings
Packaging and transporting
Collecting information
Reporting the incident
What should a first responder review as part of the organization's incident response plan?
Names and contact information of the local IH&R team
Financial reports of the organization
Marketing strategies
Employee satisfaction surveys
Which of the following is included in the escalation procedures for a first responder?
Procedures for reporting and handling a suspected incident
Daily work schedules
Vacation policies
Office decoration guidelines
What type of actions are included in the incident response plan for various types of incidents?
Containment actions
Hiring processes
Training programs
Budget planning
What is one of the main purposes of the IH&R process?
To increase financial profits
To protect networks and systems
To reduce employee workload
To enhance customer satisfaction
Why has the need for effective and structured incident handling and response become mandatory for organizations?
Due to a decrease in business data
Due to a rapid increase in threats and incidents
Due to a decline in technology use
Due to a reduction in financial losses
What can incidents compromise, leading to heavy losses?
Employee morale
Crucial business data
Marketing strategies
Customer feedback
What is the first step in the IH&R Process Flow?
Notification
Incident Recording
Preparation for IH&R
Containment
In the IH&R Process Flow, what happens if an incident is not classified as a security incident?
IH&R Team Assigned
Incident Recording
Notification
Not Classified as Security Incident
Which department is involved in the Evidence Gathering and Forensic Analysis step?
IT Support
Management and Other Depts.
Forensics Dept.
Incident Disclosure
What is the final step in the Post-Incident Activities?
Recovery
Incident Documentation
Close Incident
Review and Revise Policies
What is the first step in the preparation for incident handling and response?
Implement IR Plan
Define IR Vision and Mission
Evaluate Current IR Processes
Obtain Management Approval and Funding
Which of the following is NOT involved in the preparation phase for incident handling and response?
Defining the mission, vision, and scope
Implementing the IR Plan
Gathering systems, hardware, and software tools
Creating a plan for smooth communication
What is required to prioritize assets and services during the preparation phase?
Obtain Management Approval and Funding
Define Incident Response Criteria
Create IRT and Organize Resources
Gather systems, hardware, and software tools
What is one of the primary purposes of an Incident Response (IR) plan?
To address the mission and vision statements
To increase sales revenue
To improve customer satisfaction
To develop new products
Which of the following is a goal of an IR plan?
To meet the goals of incident response initiative
To expand the marketing team
To launch a new advertising campaign
To reduce employee turnover
What should an IR plan include to achieve its objectives?
Strategies to achieve set goals and timelines
Plans to increase market share
Methods to reduce production costs
Techniques to enhance customer loyalty
How does an IR plan add value to an organization?
By adding value to other organizational processes
By increasing the number of employees
By reducing the number of meetings
By cutting down on office supplies
What is the purpose of maintaining sufficient overall staff in IH&R training?
To reduce costs
To ensure team members have uninterrupted work time
To increase competition
To limit resources
What should be provided to the team to enhance their technical knowledge?
Financial incentives
Appropriate technical references
Vacation time
Marketing materials
What is the goal of rotating team members through incident response tasks?
To increase salaries
To build confidence in various roles
To reduce team size
To limit communication
What is the focus of developing a mentoring program for senior technical staff?
To train less experienced staff regarding the incident handling process
To increase paperwork
To limit team interaction
To reduce training time
What is the purpose of conducting training and incident handling mock drills?
To confuse the team
To make the teams familiar with the process
To reduce team morale
To limit team growth
What is the first step when an incident occurs according to the flowchart?
Close the incident report
End users call the help desk
IT department detects security alerts
IH&R team analyzes the incident
If an incident requires a response and was closed previously, what is the next step?
Close the incident report
Reopen previously closed incident
Record/update incident record
Assign IR team
What happens if an incident does not require a response?
Close the incident report
Reopen previously closed incident
Record/update incident record
Assign IR team
What is the purpose of incident analysis and validation?
To classify incidents based on severity
To determine affected resources and impact on the business
To prioritize incidents based on technical impact
To develop new security protocols
Which factors are considered in incident classification?
Business profits and losses
Employee performance and satisfaction
Severity, affected resources, and attack methodology
Customer feedback and reviews
What does incident prioritization determine?
The order of responding to security incidents
The cost of security measures
The number of incidents per month
The effectiveness of security training
What is the purpose of communicating an incident to stakeholders?
To increase the complexity of the incident
To reduce the impact by facilitating better coordination
To delay the response time
To avoid involving external agencies
Who should be notified first according to the notification process?
External agencies
The management
The public
Internal staff only
What is the primary goal of incident containment?
To prevent future incidents
To control the effect of the incident immediately after its occurrence
To identify the cause of the incident
To punish those responsible for the incident
At what phase are evidence of the incident collected and sent to the forensics department?
During the initial response
During incident containment
After the incident is resolved
Before the incident occurs
What should be done to ensure security when dealing with compromised code?
Ignore the code and continue operations
Maintain caution
Delete the code immediately
Share the code with others
What is a recommended action for data during an incident?
Delete all data
Create forensic backups to appropriate media
Share data with unauthorized users
Ignore data security
Where should data be stored to ensure safety during an incident?
In a public folder
On a personal device
In a safe location
On a shared network
What should be done with system logs and router logs during an incident?
Delete them immediately
Ignore them
Acquire and review them
Share them publicly
What should administrators and system owners be informed about during a security incident?
The latest information on the security incident
Irrelevant company news
Personal opinions
Unrelated technical updates
What is a crucial step regarding passwords during an incident?
Keep the same passwords
Change all necessary passwords and implement a strong password policy
Share passwords with others
Use simple passwords for convenience
What should be done to ensure proper documentation during an incident?
Avoid creating documents
Create documents and maintain records for every action
Only document major actions
Document actions after the incident is resolved
What is the first step in the evidence gathering and forensic analysis process?
Analyze the Evidence
Collect Evidence
Create a Forensic Investigation Report
Close the Investigation
Why is it important to create a chain of custody document during evidence gathering?
To ensure evidence is not lost
To track who has handled the evidence
To speed up the investigation process
To avoid involving law enforcement
What can organizations do with the evidence collected during the incident response process?
Ignore it
Use it to prosecute attackers
Discard it after analysis
Share it publicly
When is law enforcement required in the forensic analysis process?
When the perpetrator is not identified
When external investigation is not required
When the perpetrator is identified
When the investigation is closed
What is the primary goal of the eradication phase in incident handling and response?
To escalate the problem
To determine the cause of the incident
To remove or eliminate the root cause of the incident
To start recovery processes
Which of the following is a possible countermeasure during the eradication phase?
Install outdated software
Disable necessary services
Update antivirus software
Ignore security audits
What is the first step in the recovery process after an incident?
Restart Services and Processes
Recover Data from Backup
Eliminate the Cause of the Incident
Check if Data is Lost
What does the IH&R team do after eliminating the cause of the incident?
Shut down all systems
Restore affected systems, services, resources, and data
Ignore the incident
Create a new backup
What is the primary purpose of post-incident activities according to Step 9?
To celebrate the resolution of the incident
To improve the response against future attacks
To ignore the incident and move on
To document the incident for legal purposes
How do post-incident activities help responders according to the document?
By providing entertainment
By assessing lags in security posture, settings, and configurations
By reducing the number of team members
By increasing the budget for security
What is one of the outcomes of performing post-incident activities?
Ignoring security policies
Suggesting measures to harden security
Reducing the effectiveness of response processes
Increasing the number of incidents
