Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

1. What are the phases for the NIST security incident response? 2. What are the

ID: 3581578 • Letter: 1

Question

1. What are the phases for the NIST security incident response?

2. What are the steps for NIST forensics incident response?

3. What security incident phases the following relate to: anti-virus, wire shark, OS patching and plugins, news flash, email alert, too much delay, malware identification, process signature verification,

4. What forensics incident steps does the following relate to: memory dump, hard disk imaging, attacked web page snapshot, making a copy of hard disk image, preparing a report

5. What is the main purpose of memoryze, redline, dumpit, volatility framework, autopsy

6. What is meant by hardware encryption when we talk about TMP?

7. How did TMP 2.0 solve the problem of inflexibility of the choice of cipher suite in earlier versions?

Explanation / Answer

1) Different pahses of NIST incident response

1) Preparation: It’s always better to be prepared to handle worst situations. And Preparation is the best way to fight it, how to know incident has happened, how to recover from it and have security policies in place.

2) Identification: This is next stage to identify about the actual incident. Like you will try to find out the pattern is it something usual or any unusual pattern identified like multiple login attempt which means a person that does not have access is trying.

3) Containment: Next stage is containment. When we identify the issue then next step is to make sure that it doesn't spread and reduce its magnitude. Like if you have identified a system is infected remove it from computer network.

4) Investigate: Next once you have stopped it from spreading further or at least lower it down, it’s time to investigate why it happened in order to get to a solution to resolve it.

5) Eradication: Next stage once you have investigated what is the actual problem and why it happened then it’s the time to get rid of it.