Questions
As we conclude, here is a list of questions for you to test your knowledge regarding this chapter's material. You will find the answers in the Assessments section of the Appendix:
- Intrusion grouping and attribution cannot be assessed with a single observed tactic, technique, or sub-technique.
a. True
b. False
- This IR phase is often rushed, but it will frequently lead to reinfection.
a. Recovery
b. Preparation
c. Detection
d. Eviction
- A tactic for informing investment priorities can be accomplished by:
a. Driving the adversary back through the Kill Chain
b. Making a plan for additional resource requests
c. Using the Diamond model to describe an adversary
d. Showing how easy it would be to compromise a sensitive system
- This IR phase involves validating that steps identified in the eviction phase are carried out.
a. Preparation
b. Lessons learned
c. Containment
d. Recovery
- Improving your threat hunting skills requires purchasing training.
a. True
b. False