with verified answers
A computer incident response team manual should PRIMARILY contain
which of the following documents?
A. Risk assessment results
B. Severity criteria
C. Emergency call tree directory
D. Table of critical backup files Ans✓✓✓B is the correct answer.
Justification
B. Quickly ranking the severity criteria of an incident is a key element of
incident response.
A customer credit card database has been reported as being breached by
hackers. What is the FIRST step in dealing with this attack?
A. Confirm the incident.
B. Notify senior management.
C. Start containment.
D. Notify law enforcement. Ans✓✓✓A is the correct answer.
Justification
,A. Validating that the condition is a true security incident is the
necessary first step in determining the correct response.
A database was compromised by guessing the password for a shared
administrative account and confidential customer information was
stolen. The information security manager was able to detect this breach
by analyzing which of the following?
A. Invalid logon attempts
B. Write access violations
C. Concurrent logons
D. Firewall logs Ans✓✓✓A is the correct answer.
Justification
A. Because the password for the shared administrative account was
obtained through guessing, it is probable that there were multiple
unsuccessful logon attempts before the correct password was deduced.
Searching the logs for invalid logon attempts could, therefore, lead to the
discovery of this unauthorized activity.
A forensic team was commissioned to perform an analysis of
unrecognized processes running on a desktop personal computer. The
lead investigator advised the team against disconnecting the power in
order to:
A. prevent disk corruption.
,B. conduct a hot-swap of the main disk drive.
C. avoid loss of data in server logs.
D. avoid loss of data stored in volatile memory. Ans✓✓✓Justification
D. Disconnecting power from a system results in loss of data stored in
volatile memory. Those data could be vital for the investigation and for
understanding the extent of the impact of the event. Disconnecting
power is not recommended if analysis of running processes or the
content of volatile memory is required.
A new email virus that uses an attachment disguised as a picture file is
spreading rapidly over the Internet. Which of the following should be
performed FIRST in response to this threat?
A. Quarantine all picture files stored on file servers.
B. Block all emails containing picture file attachments.
C. Quarantine all mail servers connected to the Internet.
D. Block incoming Internet mail but permit outgoing mail. Ans✓✓✓B
is the correct answer.
Justification
B. Until signature files can be updated, incoming email containing
picture file attachments should be blocked.
A password hacking tool was used to capture detailed bank account
information and personal identification numbers. Upon confirming the
incident, the NEXT step is to:
, A. notify law enforcement.
B. start containment.
C. make an image copy of the media.
D. isolate affected servers. Ans✓✓✓B is the correct answer.
Justification
B. After an incident has been confirmed, containment is the first priority
of incident response because it will generally mitigate further impact.
A root kit was used to capture detailed accounts receivable information.
What is the next step to ensure admissibility of evidence from a legal
standpoint, once the incident has been identified and the server isolated?
A. Document how the attack occurred.
B. Notify law enforcement.
C. Take an image copy of the media.
D. Close the accounts receivable system. Ans✓✓✓C is the correct
answer.
Justification
C. Taking an image copy of the media along with preserving any other
evidence and maintaining the chain of custody is a recommended
practice to ensure legal admissibility.