Incident handling — definition?
Procedures to manage security incidents.
Scope of incident handling?
Includes attacks, insiders, availability, and IP loss.
Incident handling value?
Restores operations quickly and minimizes damage.
Incident handling goals?
Contain, eradicate, recover, and prevent recurrence.
Cyber kill chain stages?
Reconnaissance, weaponize, delivery, exploitation, installation, command & control.
Incident response lifecycle?
Preparation, detection, analysis, investigation, recovery.
Preparation stage?
Builds capability and readiness for incidents.
Protective controls?
Endpoint hardening, network segmentation, SSL/TLS interception.
Detection phase?
Spotting malicious events via sensors and logs.
Initial analysis?
Gathering context and evidence to assess incident.
Incident timeline?
Time-sorted record of attacker activities and events.
Triage questions?
Impact, requirements, scope, wild/worm potential.
IOC — definition?
Artifacts indicating malicious activity.
Yara — role?
Language for describing detection rules.
WinRM — caution?
Avoid caching credentials during IOC searches.
Incident report content?
What happened, when, team performance, improvements.
Containment — short-term?
Immediate actions to stop ongoing damage.
Containment — long-term?
Actions to prevent re-infection and ensure security.
Metti alla prova le tue conoscenze con 18 domande su Fundamentals of Cyber Incident Handling.
1. What best describes incident handling?
2. Which situation falls within the scope of incident handling?
Ripassa il corso completo nella scheda di revisione per Fundamentals of Cyber Incident Handling.
Vedi la scheda di revisione →Importa il tuo corso e l'AI genera flashcard in 30 secondi.
Generatore di flashcard