Incident Response Playbooks & Procedures Flashcards
CompTIA CySA+ CS0-004 (V4) Flashcards

| Front | Back |
| Automation opportunities with SOAR | Automate enrichment containment and ticketing actions |
| Backup verification procedure | Confirm backup integrity test restore and document results |
| Chain of custody fields | Who what when where why and how items were handled |
| Communication plan elements | Internal stakeholders external notifications and media guidance |
| Communication templates to use | Status update incident summary and action items templates |
| Containment checklist item examples | Disconnect from network disable compromised accounts and block C2 |
| Continuous improvement steps | Incorporate lessons learned update playbooks and retrain teams |
| Criteria to declare incident resolved | No active malicious activity validated recovery and monitoring period passed |
| Data exfiltration indicators | Unusual outbound volumes new cloud uploads and unknown external connections |
| Define containment types | Short term containment and long term containment |
| Escalation matrix structure | Who to contact severity based timelines and alternate contacts |
| Evidence handling chain of custody example | Initial acquisition custodian transfers storage location and signatures |
| Evidence imaging best practices | Use forensically sound tools record hashes and document steps |
| Evidence preservation essentials | Preserve disk images volatile data and system logs |
| Evidence storage best practices | Encrypted storage limited access audit trail and retention policy |
| Forensic log preservation steps | Collect central logs secure them and verify integrity with hashes |
| Incident commander responsibilities | Coordinate response allocate resources and communicate status |
| Incident identification criteria | List of signs sources and thresholds that define an incident |
| Incident lifecycle stages | Identification Containment Eradication Recovery Lessons Learned |
| Incident recordkeeping required fields | Incident ID owner timeline evidence location and actions taken |
| Incident severity classification criteria | Impact scope data sensitivity and system criticality |
| KPIs for incident response | Mean time to detect mean time to contain and recovery time |
| Legal and regulatory considerations | Preservation obligations breach notification and evidence admissibility |
| Lessons learned meeting agenda | Incident summary root causes remediation gaps action items and owners |
| Long term containment actions | Apply patches remove persistence and harden configurations |
| Malware eradication steps | Remove binaries kill persistence and update detections |
| Malware triage checklist | Collect samples capture network traffic and check IOC databases |
| Media handling guidance | Designate spokesperson avoid speculation and coordinate with legal |
| Metrics for post incident review | Number of incidents root causes mean time to remediate and closure rate |
| Network containment actions | Block malicious IPs restrict VLANs and apply ACLs |
| Notification to regulators triggers | Personal data breach large scale outage or sector specific requirements |
| Order of volatile data collection | Momentary RAM then network connections then running processes then disk |
| Playbook creation steps | Identify scope define roles map actions and test regularly |
| Playbook testing frequency | Quarterly for critical scenarios annually for low risk |
| Post incident remediation validation | Verify fixes apply monitor for recurrence and update playbook |
| Post incident report components | Timeline impact remediation actions lessons learned and metrics |
| Privacy considerations during response | Minimize data exposure preserve personal data and consult privacy officer |
| Privileged access revocation steps | Disable accounts change credentials and revoke tokens |
| Recovery validation tests | Confirm system functionality validate business processes and monitor for recurrence |
| Root cause analysis methods | 5 Whys Fishbone and timeline reconstruction |
| Root cause documentation template | Technical cause contributing factors timeline and remediation actions |
| RTO and RPO definitions | Recovery Time Objective and Recovery Point Objective with acceptable limits |
| Runbook versus playbook difference | Runbook is technical step by step playbook includes decision points and communications |
| Secure remote access procedures | Use MFA restrict to jump hosts and log all sessions |
| Short term containment actions | Isolate systems block accounts and segment network |
| SOC analyst triage steps | Collect indicators enrich alerts escalate if confirmed |
| Stakeholder notification thresholds | When business impact exceeds defined thresholds notify executives and legal |
| Tabletop exercise goals | Validate roles test playbooks and identify gaps |
| Third party vendor coordination | Identify impacted vendors request evidence and track remediation timelines |
| Triage criteria for malware vs false positive | Presence of persistence unusual outbound traffic and confirmed IOC |
About the Flashcards
Preparing for your certification requires a solid understanding of security operations and response procedures. These Flashcards for the CompTIA CySA+ exam provide a comprehensive review of essential terminology, concepts, and key ideas needed to succeed. Students can efficiently study the core components of the incident lifecycle, from initial triage and containment to eradication and recovery.
The deck also focuses on vital technical and procedural elements, including digital forensics, evidence preservation, and chain of custody documentation. By reviewing these flashcards, you will reinforce your knowledge of communication plans, playbook creation, root cause analysis, and post-incident reporting. This targeted practice ensures you are ready to identify and respond to various threats effectively.
Topics covered in this flashcard deck:
- Incident lifecycle and response stages
- Evidence preservation and forensics
- Chain of custody documentation
- Playbook and runbook procedures
- Post-incident reporting and metrics
- Containment and eradication strategies