AI Bot

Incident Response Playbooks & Procedures Flashcards

CompTIA CySA+ CS0-004 (V4) Flashcards

Study our Incident Response Playbooks & Procedures flashcards for the CompTIA CySA+ CS0-004 (V4) exam with 50+ flashcards. View as flashcards, a searchable table, or as a fun matching game.
CompTIA CySA+ CS0-004 (V4) Course Header Image
FrontBack
Automation opportunities with SOARAutomate enrichment containment and ticketing actions
Backup verification procedureConfirm backup integrity test restore and document results
Chain of custody fieldsWho what when where why and how items were handled
Communication plan elementsInternal stakeholders external notifications and media guidance
Communication templates to useStatus update incident summary and action items templates
Containment checklist item examplesDisconnect from network disable compromised accounts and block C2
Continuous improvement stepsIncorporate lessons learned update playbooks and retrain teams
Criteria to declare incident resolvedNo active malicious activity validated recovery and monitoring period passed
Data exfiltration indicatorsUnusual outbound volumes new cloud uploads and unknown external connections
Define containment typesShort term containment and long term containment
Escalation matrix structureWho to contact severity based timelines and alternate contacts
Evidence handling chain of custody exampleInitial acquisition custodian transfers storage location and signatures
Evidence imaging best practicesUse forensically sound tools record hashes and document steps
Evidence preservation essentialsPreserve disk images volatile data and system logs
Evidence storage best practicesEncrypted storage limited access audit trail and retention policy
Forensic log preservation stepsCollect central logs secure them and verify integrity with hashes
Incident commander responsibilitiesCoordinate response allocate resources and communicate status
Incident identification criteriaList of signs sources and thresholds that define an incident
Incident lifecycle stagesIdentification Containment Eradication Recovery Lessons Learned
Incident recordkeeping required fieldsIncident ID owner timeline evidence location and actions taken
Incident severity classification criteriaImpact scope data sensitivity and system criticality
KPIs for incident responseMean time to detect mean time to contain and recovery time
Legal and regulatory considerationsPreservation obligations breach notification and evidence admissibility
Lessons learned meeting agendaIncident summary root causes remediation gaps action items and owners
Long term containment actionsApply patches remove persistence and harden configurations
Malware eradication stepsRemove binaries kill persistence and update detections
Malware triage checklistCollect samples capture network traffic and check IOC databases
Media handling guidanceDesignate spokesperson avoid speculation and coordinate with legal
Metrics for post incident reviewNumber of incidents root causes mean time to remediate and closure rate
Network containment actionsBlock malicious IPs restrict VLANs and apply ACLs
Notification to regulators triggersPersonal data breach large scale outage or sector specific requirements
Order of volatile data collectionMomentary RAM then network connections then running processes then disk
Playbook creation stepsIdentify scope define roles map actions and test regularly
Playbook testing frequencyQuarterly for critical scenarios annually for low risk
Post incident remediation validationVerify fixes apply monitor for recurrence and update playbook
Post incident report componentsTimeline impact remediation actions lessons learned and metrics
Privacy considerations during responseMinimize data exposure preserve personal data and consult privacy officer
Privileged access revocation stepsDisable accounts change credentials and revoke tokens
Recovery validation testsConfirm system functionality validate business processes and monitor for recurrence
Root cause analysis methods5 Whys Fishbone and timeline reconstruction
Root cause documentation templateTechnical cause contributing factors timeline and remediation actions
RTO and RPO definitionsRecovery Time Objective and Recovery Point Objective with acceptable limits
Runbook versus playbook differenceRunbook is technical step by step playbook includes decision points and communications
Secure remote access proceduresUse MFA restrict to jump hosts and log all sessions
Short term containment actionsIsolate systems block accounts and segment network
SOC analyst triage stepsCollect indicators enrich alerts escalate if confirmed
Stakeholder notification thresholdsWhen business impact exceeds defined thresholds notify executives and legal
Tabletop exercise goalsValidate roles test playbooks and identify gaps
Third party vendor coordinationIdentify impacted vendors request evidence and track remediation timelines
Triage criteria for malware vs false positivePresence of persistence unusual outbound traffic and confirmed IOC

About the Flashcards

Preparing for your certification requires a solid understanding of security operations and response procedures. These Flashcards for the CompTIA CySA+ exam provide a comprehensive review of essential terminology, concepts, and key ideas needed to succeed. Students can efficiently study the core components of the incident lifecycle, from initial triage and containment to eradication and recovery.

The deck also focuses on vital technical and procedural elements, including digital forensics, evidence preservation, and chain of custody documentation. By reviewing these flashcards, you will reinforce your knowledge of communication plans, playbook creation, root cause analysis, and post-incident reporting. This targeted practice ensures you are ready to identify and respond to various threats effectively.

Topics covered in this flashcard deck:

  • Incident lifecycle and response stages
  • Evidence preservation and forensics
  • Chain of custody documentation
  • Playbook and runbook procedures
  • Post-incident reporting and metrics
  • Containment and eradication strategies
Share on...
Follow us on...