Instiq

5Incident Handling

Practice questions →Glossary →
  • 5.1Security event monitoring and escalation

    Covers the difference in roles between SIEM (collecting logs in one place and correlating them) and SOAR (automating and orchestrating the response after detection), the targets of network data monitoring such as packet capture and various logs, and how to identify a suspicious event ("this is not normal") and judge when to escalate, as the entry point to monitoring.

  • 5.2Digital forensics and attack attribution

    Covers frameworks for attribution—the Cyber Kill Chain (viewing an attack as time-ordered stages), MITRE ATT&CK (a catalog of attacker techniques), and the Diamond Model (organizing an event into four elements)—plus TTP (an attacker's tactics, techniques, and procedures), artifacts as evidence sources, and the evidence preservation and chain of custody that protect the authenticity of evidence, at an introductory level.

  • 5.3The impact of compliance frameworks

    Covers the correspondence of "which data each major regulation protects"—PCI-DSS (card data), HIPAA (health information), GDPR (EU personal data), FERPA (education records), and FISMA (US federal systems)—and how the reporting/notification requirements (whom to inform, and by when, in a breach) shape incident-response procedures, at an introductory level.

  • 5.4Elements of incident response

    Covers the differing roles of three document elements—policy (the intended stance), plan (how to prepare and act), and procedure (concretely what to do)—and the stages and order of the incident-response lifecycle from NIST SP 800-61: preparation -> detection/analysis -> containment/eradication/recovery -> post-incident (lessons learned), at an introductory level.