questions with accurate answers
Access Controls Ans✓✓✓Ensure that only selected or eligible
employees have access to sensitive data, critical devices, and other
necessary resources required to accomplish the assigned tasks.
After the incident, what should be reviewed and revised?
Ans✓✓✓Policies, procedures, preparation and protection.
Discussion on the incident, what can be learned, how it can be avoided,
etc.
Best practices for incident classification and prioritization? Ans✓✓✓・
Focus on high-priority security concerns first.
・Prioritize recommendations for mitigating risks to applications.
・Develop strategies to achieve short-term and long-term security
postures.
・Decide on the required resources which must be available to maintain
a consistent level of information security.
CAT 0 Ans✓✓✓Exercise / Network Defense Testing
CAT 1 Ans✓✓✓Unauthorized access.
Reporting Timeframe: Within one (1) hour of disovery/detection
,CAT 2 Ans✓✓✓Denial of service (DoS)
Reporting Timeframe: Within two (2) hours of disovery/detection if
attack is ongoing.
CAT 3 Ans✓✓✓Malicious code
Reporting Timeframe: Within one (1) hour of discovery/detection.
CAT 4 Ans✓✓✓Inappropriate usage
Reporting Timeframe: Weekly
CAT 5 Ans✓✓✓Scans/Probes/Attempted Access
Reporting Timeframe: If system is classified, report within (1) one hour
of discovery.
CAT 6 Ans✓✓✓Investigation
Depends on agency's classification and categorization.
, Common techniques used in the containment phase Ans✓✓✓・
Disabling of Specific System Services
・Changing of Passwords and Disabling of Accounts
・Complete Backups of the Infected System
・Temporary Shutdown of the Compromised System
・System Restoration
・Maintaining a Low Profile
Components of IH&R that incur cost? Ans✓✓✓・IH&R team staffing
・IH&R toolkits including software and hardware
・Communication systems
・Space requirements
・Transportation
・Fees for third-party assistance
・Power and environmental controls
・Forensic investigation
Considerations for IH&R Policies? Ans✓✓✓・Statement of
management commitment to IH&R plan
・Policy purpose and objectives
・Policy scope
・Definition of security incidents and their consequences within the
context of the organization.