questions with accurate answers
After completing an incident response process and providing a final
report to management, what step should Casey use to identify
improvement to her incident response plan?
A. Update system documentation.
B. Conduct a lessons-learned session.
C. Review patching status and vulnerability scans.
D. Engage third-party consultants. Ans✓✓✓B. Conduct a lessons-
learned session.
Alan is responding to a security incident and receives a hard drive image
from a cooperating organization that contains evidence. What additional
information should he request to verify the integrity of the evidence?
A. Private key
B. Public key
C. Hash
D. Drive capacity Ans✓✓✓C. Hash
Alejandro is an incident response analyst for a large corporation. He is
on the midnight shift when an intrusion detection system alerts him to a
potential brute-force password attack against one of the company's
critical information systems. He performs an initial triage of the event
before taking any additional action.
,What stage of the incident response process is Alejandro currently
conducting?
A. Detection
B. Response
C. Recovery
D. Mitigation Ans✓✓✓A. Detection
Alex's organization uses the NIST incident classification scheme. Alex
discovers that a laptop belonging to a senior executive had keylogging
software installed on it. How should Alex classify this occurrence?
A. Event
B. Adverse event
C. Incident
D. Policy violation Ans✓✓✓C. Incident
As part of his incident response process, Charles securely wipes the
drive of a compromised machine and reinstalls the operating system
(OS) from original media. Once he is done, he patches the machine fully
and applies his organization's security templates before reconnecting the
system to the network. Almost immediately after the system is returned
to service, he discovers that it has reconnected to the same botnet it was
part of before. Where should Charles look for the malware that is
causing this behavior?
, A. The operating system partition
B. The system BIOS or firmware
C. The system memory
D. The installation media Ans✓✓✓D. The installation media
As part of his team's forensic investigation process, Matt signs drives
and other evidence out of storage before working with them. What type
of documentation is he creating?
A. Criminal
B. Chain of custody
C. Civil
D. CYA Ans✓✓✓B. Chain of custody
As the CISO of her organization, Jennifer is working on an incident
classification scheme and wants to base her design on NIST's
definitions. Which of the following options should she use to best
describe a user accessing a file that they are not authorized to view?
A. An incident
B. An event
C. An adverse event
D. A security incident Ans✓✓✓C. An adverse event