Font size
WorksheetsCybersecurity Core Functions-IR TEAM
Total questions: 90
Worksheet time: 2hrs 5mins
CIA, an acronym for cybersecurity, determines when to escalate a cyber event to cyber incident. What does is stand for?
Counter
Intelligence
Agency
Compromise
infiltrate
Access
Confidentiality
Integrity
Availablilty
Corporate
Internal
Access controls
What does WISP stand for?
Wireless Internet Service Provider
Wide Internet Service Protocol
Wiritten information Security plan
Wide Information Service Provider
You have a confirmed CIA incident. Correctly order the Response Plan :
Start Response Log
Initiate IR team communications logging
determine origin, examine all logs with SOC
document all response measures taken
preserve evidence
What are the key security measures in the Protect function of NIST?
Access Control, Awareness and Training, Data Security, Information Protection Processes and Procedures, Maintenance, and Protective Technology
Risk Assessment, Risk Management Strategy, Supply Chain Risk Management
Anomalies and Events, Security Continuous Monitoring, Detection Processes
Response Planning, Communications, Analysis, Mitigation, Improvements
"Ground zero" has been identified and neutralized.
Please order the objectives of Phase 4 "Response" to Cyber Incident
Creating a secured and safe channel to restore external communications
Begin prioritized restoration of mission critical services
Remediation: deploy devices cleared for use. begin cleaning affected devices
Update and complete the Incident Summary Report (ISR)
Complete restoration of network functionality
Match the Log with the Correct Phase of an Incident response
Phase 1
Event Report
Phase 2
Threat Level assessment
Phase 3
Response Log
Phase 4
Restore functionality of Critical System
Phase 5
Post Incident Review Log
Put the content in order as it would be included in a public communication regarding a breach
Where could I find a Business Continuity Plan (BCP)?
In the company's written information security plan
On the company's public website
In a local library
In a personal email
Minimum needed to effectively respond to a Cyber Incident:
(a) (b) (c) (d) (e)
Your MDR detects unusual outbound network traffic that could indicate data exfiltration. Organize actions by category
Utilize Google Investigate tool to review user actions
shutdown firewall ports to destination
identify Destination address
disable user/computer account
confidentiality
Integrity
Availability
Activate full IR team
Alert Security Official
Activate MDR/BOCES security operations teams
Review Logs-MDR/Boces SOC
identify user/computer/data type
Implement Full IR Breach Plan
The MDR team has confirmed confidential Data has been exfiltrated. What next?
Stop Exfiltration: Partial/complete shutdown of corporate external/internal traffic
SOC teams identify / neutralize source of breach.
implementation of IR restore plans
Security/Public Official notifies stakeholders, and makes official Public announcement
How could I find more information on how the district data network is engineered?
By contacting the district's IT department
In the WISP, section Secure Engineering and Architecture
By attending a district board meeting
By reading the district's annual report
What considerations should be taken when communicating to Stake holders about a cyber incident?
Transparency
Not revealing information that might compromise the investigation
Protection of privacy of those who are directly affected by the data breach
recommendations of legal counsel
An Incident Response plan includes:
(a) (b) (c) (d)
The Network Security (NET) section in the WISP includes: (a)
An unreported phishing attack compromised employee credentials. The network monitoring system detects unusual activity on the user account. What order should these steps be in?
Inform the Security Offical of unfolding event
Reset: affected user credentials and sign in cookies. Change MFA notification method
determine if CIA breach occurred, update Security Official
Organize Resources by Category
Syscloud/Google DLP
Firewall
Network appliance
BR/DRAAS
Syscloud Recovery
AD Logs
Pondurance MDR Threat Intelligence SOC
Google Vault
Imaging software
"Clean" Computer reserve
Sentinel One Endpoint
isolate device
Disable user/computer account
Google Investigation Tool
Disable Firewall ports
network monitor logs
Firewall Logs
Umbrella Logs
Disconnect access to external networks
isolate networks
What considerations must be a part of restoration of critical systems after a breach?
(a) (b) (c) (d)
Prioritize the order of Restoration of District Core Systems
Internal/External communications (servers, network(s), phones)
Access to HR and finance applications
Access to HVAC system
Food and Transportation applications
Security Systems (doors, cameras)
A user reports that their files have disappeared, and they cannot access shared drives. What should the helpdesk do first?
Escalate immediately to the Incidence Response team
Verify if it is a computer or user issue before escalating to IR Team
shut down the affected system
ask if any other users are having the same experience
What doe RACI stand for?
(a)
Which phase would Legal and/or Insurance be contacted?
Phase 1-Event Reported
Phase 2-Threat assessment
Phase 3 -
Response Log
Phase 4 - Incident Summary Report
(Match the strategy to the correct NIST category.)
Documenting critical business services
IDENTIFY
Monitoring abnormal network traffic spikes.
DETECT
Evaluating strategies to manage fuutre DDOS attacks
RECOVER
Blocking malicious IP addresses and rerouting traffic
RESPOND
Increasing firewall protections and traffic filtering
PROTECT
What information is found in the Identification and Authentication (IAC) section of the WISP?
data access controls
Corporate employee access management strategies
ID badge picture options
employee break policy
The tech department learns an employee lost a company-issued laptop with sensitive customer data. what do you do?
Report incident to the Security Official
Log the device out of any cloud sessions
remotely disable
stop cloud storage sync
ask where they saw it last, and go look for it
Look on the dark web and report to the FBI
What is a Supply chain document and where can in be found in the WISP
Supply chain is a chain of supplies ordered in past 30 days found under Assets section of the WISP
The Supply Chain document is found in the Incident Response Plan (IRO) it contains all the contacts for 3rd party vendor purchases
The Supply Chain document is found in the Detection Section (DT) it contains all the contacts for party vendors in the area
The Supply Chain document is found in the Recovery Section (RSK) contains all the vaccination records
IDENTIFY: Why is asset management critical in the Identify function of NIST?
The Corporate Balance Sheet
The logistical management of company resources
To identify critical systems that need risk management
Asset management is simply inventory control.
A third-party vendor informs the company of a possible data exposure but provides limited details. What should be the next step?
Gather more information before taking further action
Terminate the contract with the vendor
Contact the Incidence Response team immediatly
Immediately inform all customers
Determining Escalation Paths Scenario: A department reports repeated malware infections on different machines. What should the cybersecurity team do?
Investigate the source of the malware and apply necessary patches to the endpoint protection software
check monitoring logs for any spikes in data exports
isolate the machines until the endpoint software is updated and to recognize the malware
determine and block the source of the malware from being accessed by the network
What does Risk Management (RSK) cover in the WISP
Risk identification
Risk assessments
Risk Ranking
Risk Remediation
The main activities in the Recover function of NIST are:
developing and improving recovery plans
Identifying clear procedures to restore mission critical applications
communicate updates to stakeholders
Monitoring and analyzing threats
Analysis is what phase of an Incident Response? It is the (a) phase.
Where could I find a history of changes made to the network?
Change Management Section (CHG)
Governance (GOV)
Compliance (CPL)
Asset management (AST)
Why have Continuous network monitoring?
(a) (b) (c)
see what people are up to
What does NIST stand for?
National Institute of Standards and Technology
National Information Security Team
Network Information Systems Technology
National Institute of Science and Technology
Multiple system become inaccssible; ransome note appears on HR computers.
Prioritize next steps
Isolate affected systems
Alert IR Security Official
Get SOC/MDR logs analysis
USE CIA to decide whether to disconnect Internet
Data Classification and Handling protections in the WISP includes information on (a) , and (b) , and (c)
Would the WISP include information on Corporate assets: (a) ?
An asset is comprised of:
Liabilities and equity
Only cash
Only physical goods
Corporate hardware and software
IDENTIFY: What is the primary purpose of a risk assessment?
To identify vulnerabilites of corporate data systems
To satisfy auditors needs and reduce liability costs
To find out Monica has too much access
To develop a comprehensive response plan
Where would I go to find out what systems we have in place for monitoring our network?
Check the IT department's documentation
Visit the company's website
WISP, Continous Monitoring section
Look in the employee handbook
Identify ways to add additional layers of security
enforcing 14 character complex password
requiring facial recognition
requiring Captcha
notifying a second device at login
What is the primary role of security awareness training in the Protect function?
To test the patience of the Data Privacy Officer
To educate staff to identify, and report social engineering attacks
To educate staff where the Acceptable use policy can be found.
To identify staff who click on everything
Where could I get detailed information on Data Backup systems in place
Data Classification Handling (DCH)
Incident Response Plan (IRP)
Businesss Continuity Plan (BCP)
Configuration Management (CHG)
Real World Reporting: Marriott Hotel Data Breach (2018) - 📌 Incident: After acquiring Starwood Hotels, Marriott discovered a long-running breach in Starwood’s system. Hackers had been exfiltrating guest data for years before Marriott realized the security flaw had been inherited.
where was the failure?
Identify: lack of review of business critical Hardware and software
The purchase price was to high!
Protect: No internal review of the protection plan for business critical applications
Detect: No system in place to monitor sensitive data movement
RECOVER: Why is a business continuity plan important in cybersecurity recovery?
To ensure the organization can continue operations during and after a cyber attack
To increase the company's profit margins
To reduce the number of employees needed in the IT department
To eliminate the need for cybersecurity measures
IDENTIFY: What are the five core functions of the NIST Cybersecurity Framework?
Identify, Protect, Detect, Respond, Recover
Plan, Execute, Monitor, Control, Close
Identify, Project, Deter, React, Recoup
Analyze, Design, Develop, Test, Deploy
Auditors are looking for security polciies for terminated personnel. Where would you direct them?
The board docs website
The Human Resources security section of the WISP
The Asset management section of the WISP
The Risk Management section of the WISP
The purpose of forensic analysis in the response process is to:
Identify the cause of an incident
Improve system performance
Enhance user experience
Increase network speed
The best practice policy for data access is (a)
Why is it important to have a pre-defined communication plan in the Respond function?
To ensure clear and efficient communication during a response
To allow for spontaneous decision-making
To avoid any form of communication
To ensure only one person is responsible for communication
During a cybersecurity class, Abigail and William are discussing the Recovery Phase of Incident Response. They mention that this phase includes:
identify vulnerabilities
update security policies
review and improve response strategies
communications process
(a) , (b) and (c) are all utilized for early detection.
"Detection tools" include:
(a) (b) (c)
Which NIST function includes activities related to security awareness?
Identify
Protect
Detect
Respond
What is the difference between Phishing and Social Engineering?
Phishing and Social engineering can be used interchangeably
Social Engineering is a general cybercrime technique and phishing is specialized form of social engineering
Phishing is a general cybercrime technique and Social engineering is a specific form of phishing
Social Engineering is a psychological attack dependent upon email phishing skills
How to Identify a Deep Fake
(Check all that apply)
eyes and eybrows don't track in unison
shadows on opposite sides of the body?
inconsitencies in the background
audio and lips don't quite sync
facial expression don't match emotions
What does "Zero Trust" security mean?
No data can be accessible from the network
no user or device should be trusted until verified
assumes a hacker could be inside your network
requires all data be encrypted at work
What steps do you take to determine if an email is real or a phishing email?
Verify the receivers address is yours
click any links, but dont fill in data right away
Verify the sender address, and any links by hovering over with mouse
Observe time sent. Is it odd?
Content is suspicious and has an alarming sense of urgent action needed
Reply back asking them to answer a question only that peson could answer
Hover over the sender email
click the link just to see where it goes
reply back and ask "really?"
A staff member recieves a questionable voice mail that sounds like the company president is requesting sensitive data. What should they do?
Forward the audio clip to IT to run deep fake detection software on it
That's the boss! Do what is asked. Now!
Contact the president in person or by phone to confirm they sent the message
Just act like they didn't recieve the voice mail.
Is it safe to email a PDF that contains confidential information?
Absolutely
Absolutely not
yes, but only if you type #secure in the subject line
Yes, but only if you type # tar in the subject line
What is the first Category of NIST?
Identify
Protect
Detect
Respond
What lessons should be learned from a cybersecurity incident recovery?
where to implement stronger security measures
where preparation was lacking
where to improve remediation procedures
determine is logging is adequate
n the Target POS Breach (2013) 📌 Incident: Attackers breached Target’s payment system by compromising an HVAC vendor with weak security. This allowed them to install malware on point-of-sale (POS) terminals, stealing 40 million credit card numbers before detection.
Which core Cybersecurity preparations were insufficient?
Identify: Critical system software vulnerabilites
Detect: lack of monitoring devices to detect data being taken off network
Protect: Install sufficient end point protection
Recover: Critical software vulnerabilities
Handling Critical Escalations: Scenario: IT discovers that an active attacker has gained administrator access to key servers. What should be done?
Inform the IR team
disable security groups wth administrator access immediately
Contact MDR and WSWHEBOCE security teams
evaluate if CIA breach occurred
require all users with administrative system access to change passwords immediatly
The Colonial Pipeline Ransomware Attack (2021)
📌 Incident: A ransomware attack on Colonial Pipeline in 2021 disrupted fuel supplies across the U.S. The attackers gained access through a compromised VPN password that lacked multi-factor authentication. Once inside, ransomware encrypted key systems, forcing Colonial Pipeline to halt operations and pay a $4.4 million ransom.
What was the root cause?
Identify:
Poor access control
Protect:
Access authentication methods were inadequate
Protect: Lack of network segmentation
Identify:
Unpatched software vulnerabilities
SolarWinds Supply Chain Attack (2020)
📌 Incident: Attackers compromised the widely used SolarWinds Orion software, injecting malware into updates that were installed by U.S. government agencies and Fortune 500 companies. This sophisticated breach remained undetected for months, allowing attackers deep network access.
What steps could have caught this much earlier
Protect: enable security logging on all network servers
Recover: Weak employee awareness
Identify: Review of third-party applications for security vulnerabilities
Detect: installing a network appliance to monitor for anamolous activity accross the network
District data is completely
inaccessible
you are locked out of your account
The clock on the computer is off
HR finance system flashes a message on employee desktop "unknown access to confidential data"
What happens first?
Alert IR Security Official
verify time and date information was accessed
Report to the FBI
click it and move on
The Equifax Data Breach (2017)
📌Incident: In 2017, Equifax, one of the largest credit reporting agencies, suffered a breach exposing personal data of 147 million Americans. The attackers exploited a known vulnerability in Apache Struts, a web application framework, which Equifax failed to patch. Once inside, hackers exfiltrated sensitive data over several months before being detected.
What was the root cause?
Respond: Equifax was quick to shut down data loss
Detect: Equifax successfully detected all data exfiltrated
Identify:
Equifax failed to assess and manage software vulnerabilities.
Equifax improved its software vulnerability management.
(a) is typically responsible for publically declaring a cyber incident as an official data breach.
According to Kevin Mitnick. What is the hardest cybercrime to defend against?
Ransomware
Malware
social engineering
Brute force password attacks
What is the best practice during the Recovery phase of an incident?
Avoid shutting down critical systems at all costs
identify root cause, isolate and eliminate it, patch systems before bringing back on line
Providing new "clean" equipment with out determining the cause of the breach
Re-image everything and open for buisness
Who conducts a cybersecurity risk assessment?
3rd party auditor
IT staff
BOCES
NYSED
In the role of an incident responder, you meticulously recorded every step and choice during a security event. This chronological record is particularly valuable for which component of the incident response report?
Executive summary
Recovery and Review
Scope
Impact
Handling Critical Escalations: Scenario: A data breach affecting customer records is confirmed. What actions should be taken?
Delete all customer records to prevent further issues.
Wait for customer complaints before taking action
Notify affected customers and regulatory bodies immediately.
Ignore the breach and continue operations as usual.
Can multi-factor authentication (MFA) be compromised?
Yes, if the user approves a fraudulent login request on their secondary device
No, MFA is completely secure
Yes, if the user is deceived by a phishing scam and clicks a malicious link
Yes, if an unauthorized person gains access to the secondary authentication device
Which document in the District Doc's Admin identifies which IR team member roles as the scope of an unfolding incident escalates?
RACI: Roles and Responsibilities spreadsheet
Incident Response Team
**Revised** Response Plan
2024 WISP-updated 10-2-24
A breach of Confidentiality is:
(a)
What is the type of breach that involves the alteration or destruction of data is
(a)
The entire business office reports they have no access to the online finance system.
If this were a Cybersecurity incident, what principle of data protection has been compromised?
Confidentialtiy
Integrity
Availability
The Hosting site is down for repair
IT detects unusual login activity from a staff account during off hours. What if anything should be done next?
Disable the staff account
contact staff member as soon as possible for confirmation
Imediately alert IR team
Contact Pondurance MDR for more log analysis
District shuts down internet due to Ransomware attack. Outlets start reporting on the attack.
Who is responsible for communications and what information is shared publicly?
Security Official
Director of Technology
Pubic Information Officer
Lega counsel
Which if any communication templates should be created and stored before a confirmed cyber incident occurs?
Public
Staff
Students
Parents
Who should be part of generating prepared communication statements to Stake holders? (a) (b)
(c)
Attackers demand payment to prevent further data leaks. What do you do?
(a) (b) (c)
Consult with Public Information Officer
In the RACI Roles and Responsibilities spreadsheet, what does the R refer to?
Recovery
Responsible
Review
Retain
In the RACI Roles and Responsibilities spreadsheet what does the C stand for?
(a)
In the RACI Roles and Responsibilities spreadsheet what does the I stand for? (a)
In the RACI Roles and Responsibilities spreadsheet what does the A stand for?
Accountable
Action needed
Assess
Activate
