answers
According to the NIST Cybersecurity Framework, which function is the
core of the DFIR process?
Identify
Protect
Detect
Respond
Recover Ans✓✓✓According to the NIST Cybersecurity Framework,
the function that is the core of the DFIR (Digital Forensics and Incident
Response) process is:
Respond
The "Respond" function within the NIST Cybersecurity Framework
emphasizes the actions organizations take in response to detected
cybersecurity incidents. This includes activities such as implementing
response procedures, mitigating the impact of incidents, and conducting
forensic analysis to understand the root causes and extent of the incident.
In the context of DFIR, the Respond function is central to the process of
effectively managing and mitigating cybersecurity incidents.
At which stage in the IR workflow will the digital forensics team
conduct their preliminary investigation?
Preparation
Identification
Detection and Analysis
,Recovery Ans✓✓✓The digital forensics team typically conducts their
preliminary investigation during the Detection and Analysis stage in the
Incident Response (IR) workflow. This stage involves identifying and
analyzing the incident to understand its scope, impact, and the
techniques used by attackers. Digital forensics plays a crucial role in
gathering evidence, examining systems, and understanding the nature of
the incident during this phase.
Complete this statement. ISO 27035 provides best practices and models
for _____.
digital forensic investigations across organizations and people.
security incident management for organizations of all sizes.
capturing and preserving digital evidence for trial.
organizations in establishing security governance and compliance
policies. Ans✓✓✓ISO 27035 provides best practices and models for:
security incident management for organizations of all sizes.
ISO 27035 is a standard that specifically focuses on the management of
security incidents. It offers guidance on preparing for, detecting,
responding to, and recovering from security incidents effectively. This
standard helps organizations of various sizes and types establish robust
incident management processes to mitigate the impact of security
incidents and protect their assets.
hich structured language is used to share threat intelligence?
STIX
TAXII
Brand reputation
,Dark web Ans✓✓✓The structured language used to share threat
intelligence is:
**STIX (Structured Threat Information eXpression)**
STIX is a standardized language for representing cyber threat
information in a structured format. It allows organizations to describe
cyber threat indicators, tactics, techniques, procedures (TTPs), and other
relevant information in a machine-readable format. STIX enables
interoperability and sharing of threat intelligence among different
security tools, platforms, and organizations.
How can an analyst overcome analysis paralysis?
Focus all their time on gathering and analyzing information.
Make a lot of small insignificant decisions and leave the big decisions to
their coworkers.
Because they are afraid of failure, they should not confront their fears or
try to find the root cause.
Rely on thought process models like OODA and OSCAR to resolve
analysis paralysis and return to making decisions. Ans✓✓✓The way an
analyst can overcome analysis paralysis is:
Rely on thought process models like OODA and OSCAR to resolve
analysis paralysis and return to making decisions.
Thought process models such as OODA (Observe, Orient, Decide, Act)
and OSCAR (Observe, Study, Consider, Assess, Review) can help
individuals break out of analysis paralysis by providing a structured
approach to decision-making. These models emphasize iterative decision
loops and continuous adaptation to changing circumstances, allowing
analysts to overcome indecision and take decisive actions based on
available information.
, How does threat intelligence help DFIR teams?
It helps them develop a fast and efficient response to an adversary.
It helps them counterattack adversaries.
It is information to be included in reports to management.
It gives them topics on which to write security blogs. Ans✓✓✓It helps
them develop a fast and efficient response to an adversary.
Threat intelligence plays a critical role in enabling DFIR teams to
understand adversaries' tactics and quickly respond to security incidents,
making it the most pertinent answer among the options provided.
If you maintain good operational security, which process is most likely
to alert the threat actor to your response?
containment
eradication
recovery
None of the above. Ans✓✓✓Maintaining good operational security
(OpSec) is crucial to avoid alerting the threat actor to your response
activities. However, if any of the processes were to potentially alert a
threat actor, it would be during containment. Containment strategies
might involve changing firewall rules, isolating network segments, or
taking systems offline, which could disrupt the attacker's access or
activities, possibly signaling to them that their presence has been
detected and actions are being taken. Nonetheless, with excellent OpSec,
even containment can often be conducted in a manner that minimizes
detection by the adversary.