KSU Incident Response From Initial Detection to Lessons Learned Discussion
Question Description
Part one
- Using an either a real life, or fictional example, describe an incident from initial detection to lessons learned.
- Why is reporting important? Describe a scenario where good reporting and note taking can help speed the resolution of an incident.
- Describe some of the tools you would need to have ready to respond to an incident, both physical and software tools should be included.
- Describe in detail the attack life cycle. Use the publicly available data from the Equifax breach as an example to demonstrate the stages in the attack.
- What are some of the network evidence sources you would expect to use in the resolution of an incident. Describe at least two, with details of what it is, and why its useful.
- Describe the triage process, and at least 3 sources of data. Why is each source important evidence?
- In several paragraphs, describe a typical process of incident response for an organization which was just informed by law enforcement that their super secret widget plans were found on the internet.
- Describe a process you might use to determine the scope of an incident. Include details like who you would talk too, and the evidence you would collect and analyze.
- Given what weve discussed about the incident response process, where do you think organizations are currently having the most trouble in responding to an incident? Give examples from breaches to backup your thoughts.
- Why is having information about an environment important when responding to an incident. Give some examples of things you can do to increase your knowledge of a network.
Part Two
- What is triage? When should this activity be preformed?
- What are two preparations which help prepare your environment for triage during an incident?
- What are two criteria for selecting a triage tool?
- What are two things that should be collected as part of triage? Why is each piece of data you selected important?
Formatting
The Questions consist of ten two-part questions. Students are required to answer both parts of the questions, in one or more paragraphs. The answer should be supported by knowledge gained by the book, lecture, or student research. It is acceptable to include APA style citations as part of a answer. This is open book / open notes / open internet. Students are encouraged to research their answers.
Answer should be formatted as one or more paragraphs consisting of a minimum of four sentences. Giving shorter answers will result in deductions. There are no upper limits on the word count or length of answers.
Students should write their answers using professional or academic English and use professional looking fonts and formatting. Any citations included should be in APA style, or some similar type of formatting.
Have a similar assignment? "Place an order for your assignment and have exceptional work written by our team of experts, guaranteeing you A results."