Incident handling — definition?
Procedures to manage security incidents.
Scope of incident handling?
Includes attacks, insiders, availability, and IP loss.
Incident handling value?
Restores operations quickly and minimizes damage.
Incident handling goals?
Contain, eradicate, recover, and prevent recurrence.
Cyber kill chain stages?
Reconnaissance, weaponize, delivery, exploitation, installation, command & control.
Incident response lifecycle?
Preparation, detection, analysis, investigation, recovery.
Preparation stage?
Builds capability and readiness for incidents.
Protective controls?
Endpoint hardening, network segmentation, SSL/TLS interception.
Detection phase?
Spotting malicious events via sensors and logs.
Initial analysis?
Gathering context and evidence to assess incident.
Incident timeline?
Time-sorted record of attacker activities and events.
Triage questions?
Impact, requirements, scope, wild/worm potential.
IOC — definition?
Artifacts indicating malicious activity.
Yara — role?
Language for describing detection rules.
WinRM — caution?
Avoid caching credentials during IOC searches.
Incident report content?
What happened, when, team performance, improvements.
Containment — short-term?
Immediate actions to stop ongoing damage.
Containment — long-term?
Actions to prevent re-infection and ensure security.
Teste seu conhecimento com 18 perguntas sobre Fundamentals of Cyber Incident Handling.
1. What best describes incident handling?
2. Which situation falls within the scope of incident handling?
Revise o curso completo na ficha de revisão para Fundamentals of Cyber Incident Handling.
Veja a ficha de revisão →Importe seu curso e a IA gera flashcards em 30 segundos.
Gerador de flashcards