Save
Upgrade to remove ads
Busy. Please wait.
Log in with Clever
or

show password
Forgot Password?

Don't have an account?  Sign up 
Sign up using Clever
or

Username is available taken
show password


Make sure to remember your password. If you forget it there is no way for StudyStack to send you a reset link. You would need to create a new account.
Your email address is only used to allow you to reset your password. See our Privacy Policy and Terms of Service.


Already a StudyStack user? Log In

Reset Password
Enter the associated with your account, and we'll email you a link to reset your password.
focusNode
Didn't know it?
click below
 
Knew it?
click below
Don't Know
Remaining cards (0)
Know
0:00
Embed Code - If you would like this activity on your web page, copy the script below and paste it into your web page.

  Normal Size     Small Size show me how

Incident response

QuestionAnswer
incident Act of violating an explicit or implied security policy
Incident response procedures Guidelines for handling security incidents
Preparation Involves strengthening systems and networks to resist attacks
Detection Identifies security incidents
Analysis Involves a thorough examination and evaluation of the incident
Containment Limits the incident's impact by securing data and protecting business operations
eradication Starts after containment and aims to remove malicious activity from the system or network
recovery Restores systems and services to their secure state after an incident
post-incident activity or lessons learned Happens after containment, eradication, and full system recovery
root cause analysis Identifies the incident's source and how to prevent it in the future
lessons learned process Documents experiences during incidents in a formalized way
after-action report Collects formalized information about what occurred
threat hunting Cybersecurity method for finding hidden threats not caught by regular security monitoring
establish a hypothesis Predicting high impact, likely events through threat modeling
profiling threat actors and activities Envisioning how potential attackers might intrude and what they aim to achieve
advisories and bulletins Published by vendors and security researchers when new TTP's and vulnerabilities are discovered
intelligence fusion and threat data Use SIEM and analysis platforms to spot concerns in the logs and real-world security threats
root cause analysis A systematic process to identify the initial source of the incident and how to prevent it from occurring again
training Ensures staff grasp processes and priorities for incident response
first responder Procedures, machine, re-image, removing a malware, change configuration settings
Manager or executive Risk vs reward, decision-making and communication, law enforcement and media
end User Report suspected incident occurring, remedial training
testing Practical exercise of incident response procedures
tabletop exercise (TTX) Exercises simulate incidents within a control framework
penetration test Simulates network intrusion based on threat scenarios
simulation Replicates real incidents for hands-on experience
simple scenarios Phishing or ransomware
complex scenarios Multi stage attacks, data breaches in coordination with external parties
Digital forensic Process of investigating and analyzing digital devices and data to uncover evidence for legal purposes
identification Ensures the safety of the scene, secures it to prevent any evidence contamination, and determines the scope of the evidence to be collected
collection Refers to the process of gathering, preserving, and documenting physical or digital evidence in various fields
order of volatility Dictate the sequence in which data sources should be collected and preserved based on their susceptibility to modification or loss
chain of custody Documented and verifiable record that tracks the handling, transfer, and preservation of digital evidence from the moment it is collected until it is presented in a court of law
disk imaging Involves creating a bit by bit or logical copy of a storage device, preserving its entire content, including deleted files and unallocated space
file carving Focuses on extracting files and data fragments from storage media without relying on the file system
analysis Involves systematically scrutinizing the data to uncover relevant information, such as potential signs of criminal activity, hidden files, timestamps, and User interactions
reporting involves documenting the findings, processes, and methodologies used during a digital forensic investigation
legal hold Formal notification that instructions employees to preserve all potentially relevant electronic data, documents, and records
electronic discovery Process of identifying, collecting, and producing electronically stored information during potential legal proceedings
data acquisition The method and tools used to create a forensically sound copy of the data from a source device, such as system memory or a hard disk
Created by: user-2044395
 

 



Voices

Use these flashcards to help memorize information. Look at the large card and try to recall what is on the other side. Then click the card to flip it. If you knew the answer, click the green Know box. Otherwise, click the red Don't know box.

When you've placed seven or more cards in the Don't know box, click "retry" to try those cards again.

If you've accidentally put the card in the wrong box, just click on the card to take it out of the box.

You can also use your keyboard to move the cards as follows:

If you are logged in to your account, this website will remember which cards you know and don't know so that they are in the same box the next time you log in.

When you need a break, try one of the other activities listed below the flashcards like Matching, Snowman, or Hungry Bug. Although it may feel like you're playing a game, your brain is still making more connections with the information to help you out.

To see how well you know the information, try the Quiz or Test activity.

Pass complete!
"Know" box contains:
Time elapsed:
Retries:
restart all cards