Incident handling — definition?
Procedures to manage security incidents.
Scope of incident handling?
Includes attacks, insiders, availability, and IP loss.
Incident handling value?
Restores operations quickly and minimizes damage.
Incident handling goals?
Contain, eradicate, recover, and prevent recurrence.
Cyber kill chain stages?
Reconnaissance, weaponize, delivery, exploitation, installation, command & control.
Incident response lifecycle?
Preparation, detection, analysis, investigation, recovery.
Preparation stage?
Builds capability and readiness for incidents.
Protective controls?
Endpoint hardening, network segmentation, SSL/TLS interception.
Detection phase?
Spotting malicious events via sensors and logs.
Initial analysis?
Gathering context and evidence to assess incident.
Incident timeline?
Time-sorted record of attacker activities and events.
Triage questions?
Impact, requirements, scope, wild/worm potential.
IOC — definition?
Artifacts indicating malicious activity.
Yara — role?
Language for describing detection rules.
WinRM — caution?
Avoid caching credentials during IOC searches.
Incident report content?
What happened, when, team performance, improvements.
Containment — short-term?
Immediate actions to stop ongoing damage.
Containment — long-term?
Actions to prevent re-infection and ensure security.
Teste tes connaissances avec un QCM de 18 questions sur Fundamentals of Cyber Incident Handling.
1. What best describes incident handling?
2. Which situation falls within the scope of incident handling?
Révisez le cours complet dans la fiche de révision de Fundamentals of Cyber Incident Handling.
Voir la fiche →Importe ton cours et l'IA génère des flashcards en 30 secondes.
Générateur de flashcards