🌍 All Study Guides📊 Dashboard📰 Blog💡 About
IBM Cybersecurity Analyst Professional Certificate • STUDY MODE

PRACTICE QUIZ

QUESTION 1 OF 23

In creating an incident response capability in your organization, NIST recommends taking 6 actions. Which three (3) actions are included on that list? (Select 3)

A
Establish a formal incident response capabilityCorrect Answer
B
Create an incident response policyCorrect Answer
C
Hold incident response drills on a regular basis
D
Develop an incident response plan based on the incident response policyCorrect Answer
QUESTION 2 OF 23

Which incident response team model would best fit the needs of a small company that runs its business out of a single office building or campus?

A
Hybrid incident response team
B
Distributed incident response team
C
Coordinating incident response team
D
Central incident response teamCorrect Answer
QUESTION 3 OF 23

True or False. An incident response team needs a blend of members with strong technical and strong soft skills?

A
TrueCorrect Answer
B
False
QUESTION 4 OF 23

Assuring systems, networks, and applications are sufficiently secure to resist an attack is part of which phase of the incident response lifecycle? CYBERATTACK FRAMEWORKS KNOWLEDGE CHECK

A
Detection & Analysis
B
Post-Incident Activity
C
PreparationCorrect Answer
D
Containment, Eradication & Recovery
QUESTION 5 OF 23

According to the IRIS Framework, during which stage of an attack would the attacker conduct external reconnaissance, alight tactics, techniques and procedures to target and prepare his attack infrastructure?

A
Continue the attack, expand network access
B
Continuous phases occur
C
Attack beginningsCorrect Answer
D
Attack objective execution
E
Launch and execute the attack
QUESTION 6 OF 23

According to the IRIS Framework, during which stage of an attack would the attacker escalate evasion tactics to evade detection?

A
Attack beginnings
B
Launch and execute the attack
C
Continuous phases occurCorrect Answer
D
Continue the attack, expand network access
E
Attack objective execution
QUESTION 7 OF 23

According to the IRIS framework, during the third phase of an attack when the attackers are attempting to escalate privileges, what should the IR team be doing as a countermeasure?

A
Build a threat profile of adversarial actors who are likely to target the company
B
Analyze all network traffic and endpoints, searching for anomalous behavior
C
Thoroughly examine available forensics to understand attack details, establish mitigation priorities, provide data to law enforcement, and plan risk reduction strategiesCorrect Answer
D
Enforce strong user password policies by enabling multi-factor authentication and restricting the ability to use the same password across systems
E
Implement strong endpoint detection and mitigation strategies
QUESTION 8 OF 23

According to the IRIS framework, during the fifth phase of an attack, the attackers will attempt execute their final objective. What should the IR team be doing as a countermeasure?

A
Enforce strong user password policies by enabling multi-factor authentication and restricting the ability to use the same password across systems
B
Thoroughly examine available forensics to understand attack details, establish mitigation priorities, provide data to law enforcement, and plan risk reduction strategiesCorrect Answer
C
Implement strong endpoint detection and mitigation strategies
D
Analyze all network traffic and endpoints, searching for anomalous behavior
E
Build a threat profile of adversarial actors who are likely to target the company
QUESTION 9 OF 23

True or False. A data breach only has to be reported to law enforcement if external customer data was compromised? INCIDENT MANAGEMENT RESPONSE AND CYBERATTACK FRAMEWORKS GRADED ASSESSMENT

A
True
B
FalseCorrect Answer
QUESTION 10 OF 23

In creating an incident response capability in your organization, NIST recommends taking 6 actions. Which three (3) actions that are a included on that list? (Select 3)

A
Establish policies and procedures regarding incident-related information sharingCorrect Answer
B
Secure executive sponsorship for the incident response plan
C
Considering the relevant factors when selecting an incident response team modelCorrect Answer
D
Develop incident response proceduresCorrect Answer
QUESTION 11 OF 23

Which incident response team model would best fit the needs of a the field offices of a large distributed organizations?

A
Hybrid incident response team
B
Coordinating incident response team
C
Central incident response team
D
Distributed incident response teamCorrect Answer
QUESTION 12 OF 23

Which incident response team staffing model would be appropriate for a small retail store that has just launched an online selling platform and finds it is now under attack? The platform was put together by its very small IT department who has no experience in managing incident response.

A
Migrate all online operations to a cloud service provider so you will not have to worry about further attacks
B
Outsource the monitoring of intrusion detection systems and firewalls to an offsite managed security service provider while leaving the response to detected incidents to current IT staff
C
Use internal IT staff only, forcing them to come up to speed as quickly as possible
D
Completely outsource the incident response work to an onsite contractor with expertise in monitoring and responding to incidentsCorrect Answer
QUESTION 13 OF 23

Which three (3) technical skills are important to have in an organization)s incident response team? (Select 3)

A
ProgrammingCorrect Answer
B
Network administrationCorrect Answer
C
System administrationCorrect Answer
D
Encryption
QUESTION 14 OF 23

Identifying incident precursors and indicators is part of which phase of the incident response lifecycle?

A
Detection & AnalysisCorrect Answer
B
Preparation
C
Containment, Eradication & Recovery
D
Post-Incident Activity
QUESTION 15 OF 23

Automatically isolating a system from the network when malware is detected on that system is part of which phase of the incident response lifecycle?

A
Containment, Eradication & RecoveryCorrect Answer
B
Post-Incident Activity
C
Detection & Analysis
D
Preparation
QUESTION 16 OF 23

According to the IRIS Framework, during which stage of an attack would the attacker send phishing email, steal credentials and establish a foothold in the target network?

A
Continue the attack, expand network access
B
Attack beginnings
C
Continuous phases occur
D
Attack objective execution
E
Launch and execute the attackCorrect Answer
QUESTION 17 OF 23

According to the IRIS Framework, during which stage of an attack would the attacker execute their final objectives?

A
Attack beginnings
B
Launch and execute the attack
C
Continue the attack, expand network access
D
Continuous phases occur
E
Attack objective executionCorrect Answer
QUESTION 18 OF 23

According to the IRIS framework, during the first stage of an attack, when the bad actors are conducting external reconnaissance and aligning their tactics, techniques and procedures, what should the IR team be doing as a countermeasure?

A
Implement strong endpoint detection and mitigation strategies
B
Thoroughly examine available forensics to understand attack details, establish mitigation priorities, provide data to law enforcement, and plan risk reduction strategies
C
Build a threat profile of adversarial actors who are likely to target the companyCorrect Answer
D
Enforce strong user password policies by enabling multi-factor authentication and restricting the ability to use the same password across systems
E
Analyze all network traffic and endpoints, searching for anomalous behavior
QUESTION 19 OF 23

According to the IRIS framework, during the fourth phase of an attack, the attackers will attempt to evade detection. What should the IR team be doing as a countermeasure?

A
Thoroughly examine available forensics to understand attack details, establish mitigation priorities, provide data to law enforcement, and plan risk reduction strategies
B
Implement strong endpoint detection and mitigation strategies
C
Enforce strong user password policies by enabling multi-factor authentication and restricting the ability to use the same password across systems
D
Build a threat profile of adversarial actors who are likely to target the company
E
Analyze all network traffic and endpoints, searching for anomalous behaviorCorrect Answer
QUESTION 20 OF 23

True or False. A data breach always has to be reported to law enforcement agencies.

A
True
B
FalseCorrect Answer
QUESTION 21 OF 23

Assuring systems, networks, and applications are sufficiently secure to resist an attack is part of which phase of the incident response lifecycle?

A
Detection & Analysis
B
Post-Incident Activity
C
PreparationCorrect Answer
D
Containment, Eradication & Recovery
QUESTION 22 OF 23

True or False. A data breach only has to be reported to law enforcement if external customer data was compromised?

A
True
B
FalseCorrect Answer
QUESTION 23 OF 23

Which three (3) technical skills are important to have in an organization’s incident response team? (Select 3)

A
ProgrammingCorrect Answer
B
Network administrationCorrect Answer
C
System administrationCorrect Answer
D
Encryption

Ready to test your recall?

In creating an incident response capability in your organization, NIST recommends taking 6 actions. Which three (3) actions are included on that list? (Select 3)

💡Select all 3 correct answers before submitting (0 of 3 selected).
A
Establish a formal incident response capability
B
Create an incident response policy
C
Hold incident response drills on a regular basis
D
Develop an incident response plan based on the incident response policy

How confident are you in this answer?