SSCP · Domain 4
Incident Response and Recovery
About 14% of the exam
The lifecycle
- Preparation
- Detection and analysis
- Escalation
- Containment
- Eradication
- Recovery and lessons learned
- Preparation decides how bad it gets
- Escalation follows the documented severity
- Contain before you clean
- Lessons learned closes the loop
Event, incident, breach
- Event
- any observable occurrence
- Alert
- an event worth a look
- Incident
- harms or threatens the organization
- Breach
- protected data actually exposed
- Severity
- impact and urgency together
- Declaration
- the formal start of response
Detect, analyze, escalate
Detect
- Alerts from the monitoring platform
- User reports still matter
- Notice from a third party
- Watch for telemetry that stops
Analyze
- Validate before declaring anything
- Scope hosts, accounts and data
- Build the timeline early
- Preserve evidence while analyzing
- Record confidence in each conclusion
Escalate
- Severity decides who is called
- Notify management and legal counsel
- Use an out-of-band channel
- Log the time of each decision
Contain, eradicate, recover
Contain
- Isolate rather than power off
- Block the command channel
- Disable compromised credentials immediately
- Short term first, then durable
Eradicate
- Remove malware and every foothold
- Close the vulnerability that allowed entry
- Rotate keys, tokens and passwords
- Rebuild when cleaning is uncertain
Recover
- Restore from verified clean backups
- Validate integrity before service returns
- Return in stages with monitoring
- Owners confirm normal operation
Restoring a backup taken after the intrusion started simply reinstalls the attacker, so date the compromise first
Forensic principles
- Legality
- act within law and policy
- Authorization
- written approval before collecting
- Order of volatility
- collect the perishable first
- Least intrusive
- change as little as possible
- Documentation
- record every action taken
- Competence
- hand over to a specialist
Evidence handling
- Photograph and label before touching
- Capture memory before shutting down
- Image the disk behind a write blocker
- Hash the image and record it
- Sign the custody form at handover
- Store evidence securely with access control
Backup strategies
- Full
- everything, longest to run
- Incremental
- changes since the last backup
- Differential
- changes since the last full
- Snapshot
- instant point in time copy
- Replication
- continuous copy to another site
- Journaling
- records every transaction change
- Immutable
- cannot be altered or deleted
- Offsite
- survives loss of the site
Redundancy
- Remove single points of failure
- Clustering fails over automatically
- Load balancing spreads and health checks
- RAID protects against disk failure
- Dual power feeds and generators
- Diverse network paths and providers
Alternate processing
- Hot site
- ready now, current data
- Warm site
- hardware ready, data restored
- Cold site
- space and power only
- Cloud failover
- capacity rented when required
- Mobile site
- brought to the location
- Reciprocal agreement
- another organization hosts you
- Manual workaround
- paper process while systems return
Restoration planning
- Restore critical functions in order
- Check the backup predates the compromise
- Verify data integrity after restoring
- Rebuild rather than restore infected systems
- Communicate progress to business owners
- Record when service formally resumed
Testing and drills
- Read-through
- Tabletop
- Walkthrough
- Simulation
- Parallel
- Full interruption
- Drills prove people know their role
- Test restores, not merely backups
- Capture findings and assign owners
- Retest whatever previously failed
Emergency response
- Life safety comes before assets
- Evacuation routes and assembly points
- Emergency contact lists kept current
- Call trees tested, never assumed
- Know who may declare a disaster
- Keep printed copies of the plan
Metrics that matter
- MTTD
- how long detection took
- MTTR
- how long recovery took
- Dwell time
- attacker time before detection
- RTO achieved
- actual against the target
- RPO achieved
- data actually lost
- Repeat incidents
- the fix did not hold
Know the order
- Lifecycle
- prepare, detect, contain, eradicate, recover
- Then
- lessons learned and plan updates
- Volatility
- memory, network state, disk, backups
- Evidence
- photograph, capture, image, hash
- Testing
- read-through up to full interruption
- Restoration
- critical functions before convenience
Reference strip: respond, prove, restore, rehearse
Respond
- Declaration, severity and escalation
- Short and long term containment
- Eradication of malware and footholds
- Credential and key rotation
Prove
- Order of volatility and memory capture
- Write blockers and forensic images
- Hashing and chain of custody
- Legal hold and authorized collection
Restore
- Full, incremental, differential, snapshot
- Replication, journaling, immutability
- Hot, warm, cold and mobile sites
- Staged return with verification
Rehearse
- Read-through and tabletop
- Simulation, parallel, full interruption
- Restore testing and failover drills
- Findings tracked to closure
Measure
- MTTD, MTTR and dwell time
- RTO and RPO actually achieved
- Repeat incident rate
- Exercise participation and outcomes
Quick exam traps
- Trap: Shutting the system down is the safest first move
- Trap: The most recent backup is always the right one
- Trap: Any technician can collect evidence for court
- Trap: A successful backup job proves you can restore
- Trap: Replication to a second site replaces backups
- Trap: The incident is over once systems are running
- Trap: Full interruption testing is the sensible starting point
cybercertprep.com · original revision sheet written from the public body of knowledge