questions with accurate answers
How should incidents be classified according to NIST? Ans✓✓✓By
functional impact, economic impact, recoverability effort, and
information impact
What are common attack vectors for security incidents?
Ans✓✓✓External/removable media, attrition, web, email,
impersonation, improper usage, loss or theft of equipment, unknown,
other
What are forensic analysis techniques used for in post-incident activity?
Ans✓✓✓To reconstruct the details of an incident
What are forensic analysis techniques used for? Ans✓✓✓To
reconstruct the details of an incident
What are the components of the cyber kill chain?
Ans✓✓✓Reconnaissance, Weaponization, Delivery, Exploitation,
Installation, Command and Control, Actions on Objectives
What are the four phases of incident response according to NIST?
Ans✓✓✓Preparation, Detection and Analysis, Containment,
Eradication and Recovery, Post-Incident Activity
, What are the key elements of an incident response policy?
Ans✓✓✓Management commitment, purpose and objectives, scope,
definitions, organizational structure, severity rating, performance
measures, reporting forms
What are the major categories of security event indicators?
Ans✓✓✓Alerts, Logs, Publicly available information, People reporting
suspicious activity
What are the NIST functional impact categories? Ans✓✓✓None, Low,
Medium, High
What are the NIST information impact categories? Ans✓✓✓None,
Privacy breach, Proprietary breach, Integrity loss
What are the three main phases of the incident management life cycle?
Ans✓✓✓Preparation, Detection and Analysis, Containment,
Eradication, and Recovery, Post-Incident Activity
What does CSIRT stand for? Ans✓✓✓Computer Security Incident
Response Team
What does OSS TMM stand for? Ans✓✓✓Open Source Security
Testing Methodology Manual