Incident Response
FortiMail
The Clients
Ticketing-Jira
Holiday Horrors
100

What are key components to include in an incident response plan during the preparation phase?

IR team, communication plan, tools/resources for detection and response, training for employees.

100

What is FortiMail?

A mail security solution that provides advanced threat protection, anti-spam, anti-phishing, and data loss prevention for email communications.

100

Which document available to everyone will tell me which reporter to put for each client?

Client list in the main DE sharepoint page

100

What is the purpose of commenting on a ticket (replying to client) immediately after creating a support ticket?

Stop the SLA by transitioning to “Waiting for Customer”

100

What is the biggest reason more incidents occur during the holiday season? 

Complacency 

200

What actions could be necessary to restore affected systems to normal operation after an incident?

restoring data from backups, verify integrity of restored systems, conducting system and security tests, and gradually bringing systems back online.

200

In a FortiMail log, you may see numbers in this format:

2:1:3:system.

What do these numbers represent?

 Policy ID’s

200

What agreement outlines the responsibilities and expectations between an MSSP and their client.

Hint:
(Most know this as a timer)

Service Level Agreement (SLA)

200

How many screenshots of IP reputation tools do we require per each potentially malicious IP?

3

200

This scam has seen recent influx during the holidays by posing as US Postal Service? 

delayed package scam text

300

Why is it important to conduct a post-incident analysis?

It helps us to understand what happened, evaluate the effectiveness of the response, and identify areas for improvement. 

300

What feature of FortiMail helps to prevent data leaks by scanning outgoing emails for sensitive information?

Data Loss Prevention or (DLP)

300

What DefendEdge client has the most firewalls?

SMS 

300

Explain the “Waiting for Support” status

Ticket SLA is either in progress and is waiting on DefendEdge to reply to the ticket or provide additional support after a client response. 

300

Which scam has seen a recent influx during the holiday period for a expedited screening program for holiday travel season. 

TSA PreCheck Scam

400

What steps can be taken to contain a security incident and prevent it from spreading?

isolating systems, disabling compromised accounts, disabling network connectivity, blocking malicious traffic, implementing temporary fixes or remediation's to prevent further damage.

400

Which FortiMail feature allows administrators to create custom policies for handling email threats?

Policy-based filtering

400

Which client has the most false positives listed on the EDR false positive list? 

BWB (Bridge Water Bank)

400

When do we place a ticket “On Hold?"

Tickets are placed on hold when immediate support is not possible as the issue is a “project” or has a necessary delay while actions are carried out. 

400

in 2023 Lapsus$ hacking group leaked source code and assets for what popular gaming developing companies future project?

Rockstar Games (GTA 6) 
500

What methods could be used to detect and identify potential security incidents?

Intrusion detection systems (IDS), analyzing logs, receiving alerts from security information and event management (SIEM)

500

Name 3 ways FortiMail's Anti-Spam feature work to reduce unwanted emails?

Blacklists, whitelists, and content filtering.

500

What 5 clients have their own individual and active Jira portals?

Reyes, Cresa, KGP, BWB, Hubgroup. 

500

Explain the difference between the Client Support portals, such as GetHelp, KGP-GetHelp, and the CTI-Support.  Why do we have individual portals?

Support portals are for DefendEdge to provide direct support to clients and handle issues. The project portals are for clients and respective hives to internally track projects or complex issues for clients that require collaboration. 

500

Which merchandise retailer in 2013 experienced a massive data breach that affected 41 million customer payment records and 70 million personal records, including names, addresses, and phone numbers? 

Target