WorksheetsIncident Response and Security Quiz 3
Total questions: 19
Worksheet time: 10mins
The (a) of an organization defines the roles and responsibilities for incident response for the CSIRT and others who will be mobilized in the activation of the plan.
Organizing the incident response planning process begins with staffing the disaster recovery committee.
True
False
The committees of the CPMT follow a set of general stages to develop their subordinate plans. In the case of incident planning, the first stage is to ____.
integrate the BIA
form the IR planning committee
identify preventive controls
develop the IR planning policy
The responsibility for creating an organization’s IR plan often falls to the ____.
project manager
forensic expert
database administrator
chief information security officer
E-mail spoofing attacks require an immediate response, typically no more than 30 minutes to one hour.
True
False
General users require training on the technical details of how to do their jobs securely, including good security practices, ____ management, specialized access controls, and violation reporting.
war gaming
“before action”
organization
password
A recommended practice for the implementation of the physical IR plan document is to organize the contents so that the first page contains the ____ actions.
“before attack”
training
testing
“during attack”
One of the primary responsibilities of the IRP team is to ensure that the ____ is prepared to respond to each incident it may face.
Semtex
IR plan
CSIRT
Catalyst
A(n) ____ is a detailed examination of the events that occurred, from first detection of an incident to final recovery.
after-action review
reactive review
proactive review
audit review
The Southeast Collegiate Cyber Defense Competition is unique in that it focuses on the operational aspect of managing and protecting an existing network infrastructure. Unlike “capture-the-flag ” exercises, this competition is exclusively a real-world ____ competition.
defensive
end-user training
offensive
hacking
A single trainer works with multiple trainees in a formal setting
After-action review
Distance learning
Formal class
Self-paced training
Can serve as a training case for future staff
Incident log
After-action review
Full-interruption test
Risk assessment
Defines roles and responsibilities for information security
Disaster recovery plan
Organization chart
Business continuity plan
IR policy
Too risky for most businesses
Distance learning
Full-interruption testing
Tabletop exercise
Simulation drill
Trainees receive a seminar presentation at their computers
Formal class
Distance learning
Self-paced course
On-site training
A source of information for developing IR policy
Website logs
Risk matrix
Organization charts
Firewall reports
An online resource for IR
CERT Coordination Center
Wikipedia
Company intranet
Cybersecurity helpdesk
A review of an unusual pattern of entries in a system log
Full audit
Signature scan
Trigger
Alert notice
Usually activated when an incident causes minimal damage with little or no disruption to business operations
Contingency plan
BIA
IR plan
DRP
