Font size
WorksheetsCySA+ Days 7 & 8
Total questions: 36
Worksheet time: 18mins
A record of a problem reported by a user or detected by a system is known as a (blank).
Requirement
Incident
Trouble Ticket
IT issue
This term refers to a security event that compromises the Confidentiality, Integrity, or Availability of an information system.
Trouble Ticket
Breach
Incident
Change Request
What is a forensic image?
What must you do prior to collecting forensic evidence during an incident response?
Establish a Chain of Custody
Obtain Authorization or Consent
Create a bit-by-bit copy of the storage device
Obtain a tamper-evident bag & seal
What can a forensic investigator perform periodically to safeguard the collected data against any accidental or intentional alterations during the investigation process?
Seal it in a tamper-evident bag
Store it in a secure location
Maintain a proper Chain of Custody
Conduct a Data Integrity Check
Which technique can be used to provide a way to verify the authenticity and integrity of data during forensic investigations?
Use tamper tape
Store it in a secure location
Digitally sign a copy of it
Sprinkle salt on some hash browns
What is the best way a forensic investigator can validate the integrity of a physical device during an incident response?
Use tamper-evident seals
Store it in a secure foot locker
Keep it in a personal safe
Keep it under 24/7 surveillance
Which Preservation technique involves making a bit-for-bit copy of an entire storage device?
Snapshot
Backup
Disk Image
Hash the disk
Which term describes assessing an incident to understand its severity and impact on the organization?
incident analysis
triage
True or False? Removing the root cause of an incident happens in the Containment phase of Incident Response.
True!
False!
This term describes a pre-defined, step-by-step guide for responding to specific types of incidents, and can even be automated using a SOAR solution.
Playbook
SOP
BC or DR? Describes the efforts the organization takes to keep the organization running during and after a disaster event.
BC
DR
BC or DR? Focuses on the immediate needs of a disaster when things are the most frantic and pressing.
DR
BC
What is the first step in the incident response process?
Identify the problem
Gather information
Establish a Theory
Preparation
These meetings must avoid pointing blame and instead focus on improving procedure.
Tabletop Exercise
Simulation
Lessons Learned
Establish a Theory
Unusual network traffic, system anomalies, unexpected file changes, malware signatures and login anomalies are all examples of ?
Incidents
IoCs
Threats
Unauthorized access attempts
Alvin received an alert from an IDS in the network, and it indicated a severity level of 1. Should he respond immediately or focus on more severe threats first, to ensure proper utilization of resources?
Respond immediately! All hands on deck, Captain Bryan!
A rating of "1" isn't that bad... focus on the others first!
Which tool does a SOAR solution utilize to interact with other security tools and systems seamlessly?
SIEM
VPN
SSH
API
A cybersecurity analyst noticed a potential network breach, so she immediately called the Incident Response team on his VoIP phone. What did she do wrong?
She didn't analyze the data first.
Nothing! Sounds like a timely response to me.
She potentially tipped off the attacker.
Her first response should have been to take steps to halt the incident's progression prior to making phone calls.
If a law firm wanted to ensure the preservation of digital evidence for a case, what would they likely implement?
Chain of Custody
Legal Hold
Preservation Request
Lawful Hold
This document shows each person who had access to the evidence, the actions they took, and the date/time that they accessed it.
Legal Hold
Evidence Document
Chain of Custody
Custody Agreement
This term describes the process of restoring a system to its original state by wiping it clean and installing a fresh OS, along with any applications the end user may need.
Restore (system defaults)
Reimage
Remote Wipe
Disk Image
What is the purpose of Containment?
Isolate
Prevent spread
Segment
Air gap
What is the last step of the digital forensics process?
Legal Hold
Securely store the evidence
Lessons Learned
Reporting
What's the best option of the following tools that can be used to determine the sequence of events of an incident?
Event logs
SIEM report
Timeline
Timestamps
What term describes matching an incident to a specific threat actor or group?
Identification
Threat Profiling
Attribution
Blame
True or False? A company recently experienced a massive data breach. The Public Relations representative did a great job at managing the fallout from the breach, showing that the company is resilient. The way it was handled will likely give the company a competitive advantage.
True
False
Choose the greatest benefit of engaging with the media to manage public perception.
Promotes the company's services
Controls the narrative of a negative situation
Increases brand awareness
Reassures the public that the company is legitimate
True or False? New incidents should be escalated to the relevant personnel who have the authority to address it.
False
True
When dealing with GDPR customers, how many hours would a company have before they must notify them of a breach?
24
72
60 days
48
If criminal activity may have taken place in your organization, what should you do first?
Ask the incident response team to conduct an initial assessment
Notify law enforcement
Seek legal counsel
Notify relevant stakeholders
There was a recent PHI breach that affected 750 employees. How long does the company have before they must contact the US Department of Health and Human Services (HHS)?
72 hours
30 days
60 days
End of the calendar year
In the context of CySA+, MTTR stands for the following (choose 3).
Mean Time To Recover
Mean Time To Respond
Mean Time To Remediate
Mean Time To Repair
Which of the following is a brief overview of a larger report?
Executive Summary
Outline
Executive Series
Lessons Learned
This term describes the quantity of alerts generated by security monitoring tools.
Alert Tuning
Alert Volume
Alert Monitoring
Alert Frequency
Choose the benefit of Root Cause Analysis.
Holistic understanding
Risk Exposure
Problem identification
Symptom identification
