Questions
Answer the following questions to test your knowledge of this chapter:
- During a security incident, a team member was able to refer to known documentation and databases of attack vectors to aid the response. What is this an example of?
- Event classification
- A false positive
- A false negative
- A true positive
- During a security incident, a team member responded to a SIEM alert and successfully stopped an attempted data exfiltration. What can be said about the SIEM alert?
- It's a false positive.
- It's a false negative.
- It's a true positive.
- It's a true negative.
- During a security incident, a senior team leader coordinated with members already dealing with a breach. They were told to concentrate their efforts on a new threat. What process led to the team leader's actions?
- Preparation
- Analysis
- Triage event
- Pre-escalation tasks
- A CSIRT team needs to be identified, including leadership with a clear reporting and escalation process. At what stage...