skip to content

Incident Response Lifecycle

You declare what triage called adversarial, cut the intruder out without losing the evidence that proves it, come back clean, and answer for it afterwards. Interviewers open on ransomware.

on this pageshow

explore

questions

page 2 of 2

An intruder held domain admin for forty days — how do you decide which backups you can trust?

level: middleimportance: should knowfreq 52%

basics

~20 s

Trust turns on two questions: was the copy written before they got in, and could they have altered or deleted it afterwards. Domain-level privilege reached the backup platform, so offline or immutable copies and its own audit records decide it.

open as a page

Why is the Active Directory krbtgt account password reset twice during eradication?

level: middleimportance: should knowfreq 52%

basics

~20 s

Active Directory keeps the current and the previous krbtgt key, so one reset leaves the old key valid and forged tickets minted with it still work. Reset twice, allowing the first change to replicate to every domain controller in between.

open as a page

Minutes before a planned containment cut, appliance egress spikes and an inbox rule is deleted. What do you conclude?

level: middleimportance: should knowfreq 46%

basics

~20 s

Conclude they know. The flow records prove bytes left to that destination, not what those bytes were, and the rule deletion is a dated act of evidence removal. Cut now, and reopen the scope question.

open as a page

An EDR rule auto-quarantines hosts in a live intrusion you are still scoping. How do you quiet it without going blind?

level: middleimportance: should knowfreq 41%

basics

~20 s

Separate detection from response: leave the rule firing and collecting, and disable only its quarantine action. Disabling the rule itself blinds the case. Time-box the suppression to the planned cut and staff a human for the hits.

open as a page

In a ransomware playbook, what must pre-delegated authority to disconnect the virtualisation management network specify?

level: middleimportance: should knowfreq 50%

basics

~20 s

A tight observable trigger, a bounded scope with explicit never-touch systems, an isolation method that preserves evidence, a notify-within deadline, who may reconnect and on what proof, and contractual cover so the delegate actually acts.

open as a page

A compromised identity has read-only access everywhere and no write anywhere — why can that still be a top-severity intrusion?

level: middleimportance: should knowfreq 61%

basics

~20 s

Because severity is graded on what was reached, not on what was broken. A directory-wide, warehouse-wide reader reaches regulated records, secrets left in resource metadata, and a complete map of the estate. Confidentiality loss requires no write at all.

open as a page

Why is a retained DFIR firm hired through outside counsel, and what changes in how you write findings?

level: middleimportance: should knowfreq 46%

basics

~20 s

Counsel engages the firm so its work informs legal advice and may be shielded from later disclosure. Notes then carry observed artefacts, sources and timestamps, never speculation about fault. The underlying logs and evidence are never protected.

open as a page

Before you agree to watch a live intruder instead of isolating the host, what must be written down?

level: seniorimportance: should knowfreq 56%

basics

~20 s

The named behaviours that trigger immediate containment, a time box with a review point, the specific scope questions the watch is meant to answer, the person who authorised it, and who is on the keyboard with the cut pre-staged and rehearsed.

open as a page

After forty days of domain-admin access, do you restore the domain controllers or rebuild the forest?

level: seniorimportance: should knowfreq 44%

basics

~20 s

The decision is about the directory's contents, not the servers. Restore controllers from a pre-compromise system state when you can bound what changed; rebuild the forest when the privileged object graph can no longer be vouched for.

open as a page

Your managed service provider says it was breached and its remote-support account in your estate may have been used — how do you scope it?

level: seniorimportance: should knowfreq 57%

basics

~20 s

Scope by the access, not by your alerts. Enumerate everything that identity could reach and every secret it could read, then reconstruct what it actually did from records you hold, and remediate the access whether or not misuse is proven.

open as a page

Twenty hours into a declared intrusion the scope doubles — why is upgrading the severity grade easier than downgrading it?

level: seniorimportance: should knowfreq 56%

basics

~20 s

Upgrading rests on positive evidence: new reach you can point at. Downgrading requires proving the earlier reach never existed, and a missing log record is not that proof — the logging may have been off, expired, or blind to the technique.

open as a page

You declared an intrusion at 02:00 on a burst of admin password-reset events that proved to be an approved bulk-reset script — what should the bar have required first?

level: seniorimportance: should knowfreq 44%

basics

~20 s

One authorisation check before the word, time-boxed. Windows 4724 proves a privileged reset happened, never who authorised it, so the bar must require the change record and a call to the named system owner, declaring anyway if nobody answers.

open as a page

An executive wants your incident briefing to name the attacker group. How do you answer?

level: principalimportance: should knowfreq 38%

basics

~20 s

Give the executive the decisions they actually need rather than the name they asked for, and state what the evidence supports and what it does not. Assessments of who is responsible belong in a separate owned product, not a status briefing.

open as a page

A desk head refuses to let you isolate a trading workstation with a live intruder on it. What now?

level: principalimportance: should knowfreq 42%

basics

~20 s

Neither the SOC nor the desk head owns that call alone. Price both outcomes, escalate to the executive accountable for the firm's risk, offer a bounded watch with tripwires or a move to a spare workstation, and record who decided what and when.

open as a page

The platform owner won't rebuild 291 servers you can't prove are clean — how do you declare eradication complete?

level: principalimportance: should knowfreq 39%

basics

~20 s

Stop claiming proof and state criteria instead: what was swept, what could not be, what compensates for the gap, and which named business owner accepts the remainder. Then run a time-boxed re-entry watch with specific tripwires and conditions that reopen the incident.

open as a page

Your mass credential reset covers 4,000 accounts but the helpdesk can re-verify 400 a day. How do you scope it?

level: principalimportance: should knowfreq 38%

basics

~10 s

Rank the population by privilege and evidence of adversary use rather than resetting everyone equally, verify identity out-of-band, apply compensating controls to the un-reset tail, and have a named executive accept the residual exposure.

open as a page

Your earliest logs aged out at 90 days and an executive wants one intrusion start date — what do you commit to?

level: principalimportance: should knowfreq 42%

basics

~20 s

Commit to what the evidence supports: earliest observed activity with its date and citation, plus an explicit statement that the window before the retention edge cannot be assessed. Never convert an absence of records into a start date.

open as a page

Counsel wants a suspected insider's account left live to gather evidence; the CISO wants it disabled now. Who decides?

level: principalimportance: should knowfreq 38%

basics

~20 s

Neither function outranks the other, so the tie goes to the accountable executive the plan names, with HR present because cutting an employee's access is an employment act. Take the reversible option, time-box it, record the rationale.

open as a page

Why is an intruder operating through your licensed RMM agent hard to contain by isolating one host?

level: middleimportance: nice to knowfreq 34%

basics

~20 s

Because the access path is the remote-management tenant, not the machine. The console can open a session on any enrolled host, and blocking the vendor's cloud at the perimeter cuts your own IT operations everywhere at once.

open as a page

You notified on partial facts and the affected-record count later grew tenfold — how do you handle it?

level: seniorimportance: nice to knowfreq 27%

basics

~10 s

Supplement the original filing with the new figure and the analytic step that produced it. Growth explained by a widened search reads as diligence; growth contradicting an earlier assurance does not.

open as a page

How do you tell 4,000 staff to stop using the company chat when the intruder is reading it?

level: seniorimportance: nice to knowfreq 40%

basics

~20 s

Send a short instruction that changes behaviour, carries no findings, and can be verified without clicking anything, through a path the adversary does not control. Write it assuming the intruder and the press both read it.

open as a page

A foothold artefact predates your intrusion timeline by six months: how do you test it before moving patient zero back?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

Treat it as a hypothesis, not a finding. Test for positive linkage — shared unique artefacts, credentials, infrastructure — check continuity across the gap, and reconcile it against records of authorised activity before re-dating anything.

open as a page

An extortion leak site lists your company with a 2.1 TB claim and a 72-hour timer — what does that prove?

level: seniorimportance: nice to knowfreq 31%

basics

~20 s

It proves the actor published a claim and, if a sample is posted, possesses at least what is in that sample. The volume figure is unverified, the timer is a negotiating lever they set, and absence from the site would prove nothing.

open as a page

A departing employee bulk-exported an HR dataset. Who must you consult before examining their HRIS audit trail?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

Examining a named employee's records needs HR as data owner, the privacy office for a documented lawful basis, counsel for the legal posture, and in several European jurisdictions consultation with the works council before behaviour-monitoring data is analysed.

open as a page

Your post-intrusion collection requirement is refused on cost by the platform owner - what does the closure document record?

level: principalimportance: nice to knowfreq 32%

basics

~20 s

Record the requirement as raised, the refusal, who decided it and when, the exposure that remains in operational terms, any compensating measure you will actually perform, and a date to revisit. Never quietly delete the requirement.

open as a page

Platform engineering auto-deletes flagged pods, so every intrusion loses its evidence - what do you negotiate?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Not a veto on auto-remediation but a quarantine mode: replace the workload immediately, then hold the original with egress denied and credentials revoked for a hard-capped window, reaped automatically, invoked under standing authority by the incident lead.

open as a page

Finance rejects the restore point that predates the intrusion — who owns that call and how do you frame it?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

The trade is certain business loss against residual adversary presence, so the accountable business owner takes it, not the responder. Your job is to state honestly what each option costs, offer the middle paths, and record what was accepted.

open as a page

The breached provider refuses to share the logs that would show whether its account touched your estate — what do you do?

level: principalimportance: nice to knowfreq 32%

basics

~20 s

Stop waiting for evidence you cannot compel. Set an explicit working assumption that the access was used, remediate on that basis, escalate commercially for narrow tenant-specific artefacts, and report the residual uncertainty plainly rather than as an all-clear.

open as a page

A data owner disputes the classification label on tables an intruder read — how do you settle the intrusion's grade?

level: principalimportance: nice to knowfreq 33%

basics

~20 s

Grade on what the columns actually contain, not only on the label. Hold the conservative grade as explicitly provisional, sample the real values from the columns the query records name, escalate to whoever is accountable for the label rather than to whoever disputes it, and record the basis.

open as a page

Your cyber policy demands prompt notice and panel counsel, and only the CISO may declare — how do you make out-of-hours declaration workable?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Split the authority. Pre-delegate in writing to a named duty officer the right to declare and contain against a standing threshold, and keep the acts that bind the company on a pre-cleared path with named fallbacks.

open as a page

showing 31–60 of 60