1. Which of the following is the MOST reliable way to ensure network security incidents are identified as soon as possible?
A) Collect and correlate IT infrastructure event logs. B) Conduct workshops and training sessions with end users. C) Install stateful inspection firewalls. D) Train help desk staff to identify and prioritize security incidents.
2. Which of the following would be MOST helpful to reduce the amount of time needed by an incident response team to determine appropriate actions?
A) Providing annual awareness training regarding incident response for team members B) Defining incident severity levels during a business impact analysis (BIA) C) Validating the incident response plan against industry best practices D) Rehearsing incident response procedures, roles, and responsibilities
3. Which of the following is the BEST way for an organization to ensure that incident response teams are properly prepared?
A) Conducting tabletop exercises appropriate for the organization B) Providing training from third-party forensics firms C) Documenting multiple scenarios for the organization and response steps D) Obtaining industry certifications for the response team
4. The MOST important reason to have a well-documented and tested incident response plan in place is to:
A) standardize the chain of custody procedure B) facilitate the escalation process C) promote a coordinated effort. D) outline external communications
5. Which of the following is the MOST important security consideration when developing an incident response strategy with a cloud provider?
A) Escalation processes B) Security audit reports C) Technological capabilities D) Recovery time objective (RTO)
Leave a comment