100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

SSCP - Ch. 1 - Security Fundamentals questions with complete verified solutions (graded A+).

Rating
-
Sold
-
Pages
11
Grade
A+
Uploaded on
21-11-2024
Written in
2024/2025

SSCP - Ch. 1 - Security Fundamentals questions with complete verified solutions (graded A+).

Institution
Official ² SSCP
Course
Official ² SSCP









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Official ² SSCP
Course
Official ² SSCP

Document information

Uploaded on
November 21, 2024
Number of pages
11
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

ISC2 SSCP: Incident Response
and Recovery test questions
and answers 2025
Incident Response Plane Elements
- state of purpose
- strategies and goals for incident response
- approach to incident response
- communication with other groups
- senior leadership approval
CONSULT: NIST SP 800-61
Incident Communication Plan
- Ensures all participants have timely, accurate info
- Limit external communications to trusted parties
- Comply with legislative or regulatory notification requirements
Secure Communication
prevents inadvertent information leaks
Monitoring is crucial to ___________
incident identification
Incident Data Sources
ids/ips
firewalls
authentication systems
integrity monitors
vulnerability scanners
system event logs
netflow records
antimalware packages
SIEM (Security Incident and Event Management)
Security solution that collects information from diverse sources, analyzes
it for signs of security incidents, and retains it for later use.
First responders should _________
isolate affected systems

, EXAM TIP: The highest priority of a first responder must be containing
damage through isolation
Escalation and Notification Objectives
Evaluate incident severity based upon impact
Escalate response to an appropriate level
notify management and other stakeholders
Triaging Incidents
Low Impact - minimal potential to affect security, handled by first
responders, don;t require after hour response

Moderate Impact - significant potential to affect security, trigger incident
response team activation, require prompt notification to management

High Impact - may casue critical damage to informatio systems, justify an
immediate full response, requires immediate notification to senior
management, demand full mobilization of incident response team
Containment Strategy Evaluation
1. Damage potential
2. Evidence preservation
3. Service availbaility
4. Resource requirements
5. expected effectiveness
6. Solution time frame
A containment measure should balance ________ needs and _________
objectives
business, security
Mitigation ends with ___________
stablility
Containment
Limits the damage
Three activites to contain damage of a security incident
1. Segmentation - divide networks into logical segments, grouped by
types of users or systems
2. Isolation - compromised system is moved to a network that is
completely disconnected from the rest of the network.
3. Removal - completely disconnects impacted systems from any network.
Eradicaiton

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BRAINBOOSTERS Howard Community College
View profile
Follow You need to be logged in order to follow users or courses
Sold
673
Member since
2 year
Number of followers
251
Documents
23390
Last sold
6 hours ago

In this page you will find all documents , flashcards and package deals offered by seller BRAINBOOSTERS

4.5

341 reviews

5
266
4
30
3
21
2
5
1
19

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions