The first phase is pre________________. Organizations must prepare to mitigate the likelihood, risk, and impact of a security incident by documenting procedures, establishing staffing plans, and educating users. pre________________ sets the foundation for successful incident response. For example, organizations can create incident response plans and procedures that outline the roles and responsibilities of each security team member.

Manage Security Risks: Quiz 7

Quiz
•
Computers
•
Professional Development
•
Hard
John Coder
FREE Resource
8 questions
Show all answers
1.
FILL IN THE BLANK QUESTION
1 min • 1 pt
2.
FILL IN THE BLANK QUESTION
1 min • 1 pt
The second phase is det___________ and ana___________. The objective of this phase is to detect and analyze events using defined processes and technology. Using appropriate tools and strategies during this phase helps security analysts determine whether a breach has occurred and analyze its possible magnitude.
3.
FILL IN THE BLANK QUESTION
1 min • 1 pt
The fifth phase is po_______-incident activity. This phase includes documenting the incident, informing organizational leadership, and applying lessons learned to ensure that an organization is better prepared to handle future incidents. Depending on the severity of the incident, organizations can conduct a full-scale incident analysis to determine the root cause of the incident and implement various updates or improvements to enhance its overall security posture.
4.
FILL IN THE BLANK QUESTION
1 min • 1 pt
The third phase is conta___________. The goal of conta___________ is to prevent further damage and reduce the immediate impact of a security incident. During this phase, security professionals take actions to contain an incident and minimize damage. conta___________ is a high priority for organizations because it helps prevent ongoing risks to critical assets and data.
5.
FILL IN THE BLANK QUESTION
1 min • 1 pt
Playbooks sometimes cover specific incidents and vulner___________. These might include ransomware, vishing, business email compromise (BEC), and other attacks previously discussed. Incident and vulnerability response playbooks are very common, but they are not the only types of playbooks organizations develop.
Each organization has a different set of playbook tools, methodologies, protocols, and procedures that they adhere to, and different individuals are involved at each step of the response process, depending on the country they are in. For example, incident notification requirements from government-imposed laws and regulations, along with compliance standards, affect the content in the playbooks. These requirements are subject to change based on where the incident originated and the type of data affected.
6.
FILL IN THE BLANK QUESTION
1 min • 1 pt
The fourth phase in an incident response playbook is erad___________ and rec___________. This phase involves the complete removal of an incident's artifacts so that an organization can return to normal operations. During this phase, security professionals eliminate artifacts of the incident by removing malicious code and mitigating vulnerabilities. Once they've exercised due diligence, they can begin to restore the affected environment to a secure state. This is also known as IT restoration.
7.
FILL IN THE BLANK QUESTION
1 min • 1 pt
The sixth and final phase in an incident response playbook is coordination. coor__________ involves reporting incidents and sharing information, throughout the incident response process, based on the organization's established standards. coor__________ is important for many reasons. It ensures that organizations meet compliance requirements and it allows for coor__________ response and resolution.
8.
FILL IN THE BLANK QUESTION
1 min • 1 pt
Playbooks are also used with SOAR tools. SOAR tools are similar to SIEM tools in that they are used for threat monitoring. SOAR is a piece of software used to auto___________ repetitive tasks generated by tools such as a SIEM or managed detection and response (MDR). For example, if a user attempts to log into their computer too many times with the wrong password, a SOAR would automatically block their account to stop a possible intrusion. Then, analysts would refer to a playbook to take steps to resolve the issue.
Similar Resources on Quizizz
10 questions
IT ENGLISH: Technical Terminology - Alpha Software

Quiz
•
Professional Development
11 questions
Security Incident Management

Quiz
•
Professional Development
10 questions
Software Development Lifecycle for Mobile Apps

Quiz
•
Professional Development
10 questions
Mitigation Techniques and Controls

Quiz
•
Professional Development
11 questions
Ansible part 2

Quiz
•
Professional Development
10 questions
Cyber Incident Response Quiz

Quiz
•
Professional Development
10 questions
UD Cybersecurity Pro

Quiz
•
Professional Development
8 questions
Elastic Essentials Quiz

Quiz
•
Professional Development
Popular Resources on Quizizz
10 questions
Chains by Laurie Halse Anderson Chapters 1-3 Quiz

Quiz
•
6th Grade
20 questions
math review

Quiz
•
4th Grade
15 questions
Character Analysis

Quiz
•
4th Grade
12 questions
Multiplying Fractions

Quiz
•
6th Grade
30 questions
Biology Regents Review #1

Quiz
•
9th Grade
20 questions
Reading Comprehension

Quiz
•
5th Grade
20 questions
Types of Credit

Quiz
•
9th - 12th Grade
50 questions
Biology Regents Review: Structure & Function

Quiz
•
9th - 12th Grade