Containment
Evidence
Phases
Super Hero
100

Which containment technique is the strongest possible response to an incident?

Removal

100

What agency recommends investigations maintain evidence logs?

NIST (National Institute of Standards and Technology)

100

What is the 1st activity that takes place after an incident occurs?

Containment


100

What super hero is fast?

Flash

200

Containment activities seek to limit the ________ of an incident.

Impact / spread

200

Why would evidence be preserved?

Criminal or civil action

200

What is the 2nd activity that takes place after an incident occurs?

Eradication

200

How did Captain America get his powers?

Super Soldier Serum

300

What containment strategy moves a suspected compromised system to a quarantine VLAN?

Segmentation

300

How is a company drive with sensitive information disposed of?

Purge

300

What is the 3rd activity that takes place after an incident occurs?

Recovery

300

Who is not an Avenger?  Thor, Hulk, Batman, Iron Man

  Batman

400

What evidence is volatile in nature and may not be available later?

Memory

400

How is a flash drive with sensitive information disposed of that belongs to an outside contractor?

Destruction

400

Which phase focuses on restoring normal operations?

Recovery

400

Who is not on the Justice League?  Batman, Captain America, Green Lantern, Aquaman

Captain America

500

What is critical to conducting a solid incident recovery effort?

Root cause of the attack

500

Another word for purging data?

Degaussing

500

What is one of the post incident activities?

Change Control Processes, After Action session, and Final Report

500

Who is the lead female in the Justice League?

Wonder Woman