Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR)
134 questions across 1 topics, with suggested answers, explanations where available, and imported community discussion. The first 13 questions are free to preview.
Topics
| # | Topic | Questions | Free |
|---|---|---|---|
| 1 | Forensics Techniques | 134 | 13 |
Preview
13 of 134 accessibleWhat is the anti-forensics technique known as steganography?
An employee receives an email from a "trusted" person that contains a hyperlink involving malvertising. The employee clicks the link, and malware is downloaded. An information analyst notices an alert in the SIEM and engages the cybersecurity team to analyze the incident according to the incident response plan. Which event detail should be included in this root cause analysis?
An incident response team recommends changes after reviewing a recent compromise in which: - A large number of events and logs were involved. - Team members could not identify anomalous behavior and escalate it promptly. - Several network systems were affected because detection was delayed. - Security engineers mitigated the threat and restored systems to a stable state. - The issue recurred shortly afterward and systems became unstable again because the correct information was not collected during the initial identification phase. Which two recommendations should be made to improve the incident response process? (Choose two.)