Incident Response Lifecycle
You declare what triage called adversarial, cut the intruder out without losing the evidence that proves it, come back clean, and answer for it afterwards. Interviewers open on ransomware.
on this pageshowhide
explore
- Declaring an Intrusion24 questions
- Who Makes The Call4 questions
- Grading What They Reached4 questions
- Patient Zero And Spread4 questions
- Beyond The Security Team4 questions
- Ransomware Playbook4 questions
- The Intrusion Someone Else Found4 questions
- Cutting The Adversary Out20 questions
- Isolate Now Or Watch4 questions
- Tipping Them Off4 questions
- Revoking Their Access4 questions
- Proving They Are Gone4 questions
- Coming Back Clean4 questions
- Answering For It16 questions
- Evidence Versus Speed4 questions
- The Clock You Started4 questions
- When The Intruder Listens5 questions
- The Detection Gap3 questions
questions
page 2 of 2An intruder held domain admin for forty days — how do you decide which backups you can trust?
basics
~20 sTrust turns on two questions: was the copy written before they got in, and could they have altered or deleted it afterwards. Domain-level privilege reached the backup platform, so offline or immutable copies and its own audit records decide it.
Why is the Active Directory krbtgt account password reset twice during eradication?
basics
~20 sActive Directory keeps the current and the previous krbtgt key, so one reset leaves the old key valid and forged tickets minted with it still work. Reset twice, allowing the first change to replicate to every domain controller in between.
Minutes before a planned containment cut, appliance egress spikes and an inbox rule is deleted. What do you conclude?
basics
~20 sConclude they know. The flow records prove bytes left to that destination, not what those bytes were, and the rule deletion is a dated act of evidence removal. Cut now, and reopen the scope question.
An EDR rule auto-quarantines hosts in a live intrusion you are still scoping. How do you quiet it without going blind?
basics
~20 sSeparate detection from response: leave the rule firing and collecting, and disable only its quarantine action. Disabling the rule itself blinds the case. Time-box the suppression to the planned cut and staff a human for the hits.
In a ransomware playbook, what must pre-delegated authority to disconnect the virtualisation management network specify?
basics
~20 sA tight observable trigger, a bounded scope with explicit never-touch systems, an isolation method that preserves evidence, a notify-within deadline, who may reconnect and on what proof, and contractual cover so the delegate actually acts.
A compromised identity has read-only access everywhere and no write anywhere — why can that still be a top-severity intrusion?
basics
~20 sBecause severity is graded on what was reached, not on what was broken. A directory-wide, warehouse-wide reader reaches regulated records, secrets left in resource metadata, and a complete map of the estate. Confidentiality loss requires no write at all.
Why is a retained DFIR firm hired through outside counsel, and what changes in how you write findings?
basics
~20 sCounsel engages the firm so its work informs legal advice and may be shielded from later disclosure. Notes then carry observed artefacts, sources and timestamps, never speculation about fault. The underlying logs and evidence are never protected.
Before you agree to watch a live intruder instead of isolating the host, what must be written down?
basics
~20 sThe named behaviours that trigger immediate containment, a time box with a review point, the specific scope questions the watch is meant to answer, the person who authorised it, and who is on the keyboard with the cut pre-staged and rehearsed.
After forty days of domain-admin access, do you restore the domain controllers or rebuild the forest?
basics
~20 sThe decision is about the directory's contents, not the servers. Restore controllers from a pre-compromise system state when you can bound what changed; rebuild the forest when the privileged object graph can no longer be vouched for.
Your managed service provider says it was breached and its remote-support account in your estate may have been used — how do you scope it?
basics
~20 sScope by the access, not by your alerts. Enumerate everything that identity could reach and every secret it could read, then reconstruct what it actually did from records you hold, and remediate the access whether or not misuse is proven.
Twenty hours into a declared intrusion the scope doubles — why is upgrading the severity grade easier than downgrading it?
basics
~20 sUpgrading rests on positive evidence: new reach you can point at. Downgrading requires proving the earlier reach never existed, and a missing log record is not that proof — the logging may have been off, expired, or blind to the technique.
You declared an intrusion at 02:00 on a burst of admin password-reset events that proved to be an approved bulk-reset script — what should the bar have required first?
basics
~20 sOne authorisation check before the word, time-boxed. Windows 4724 proves a privileged reset happened, never who authorised it, so the bar must require the change record and a call to the named system owner, declaring anyway if nobody answers.
An executive wants your incident briefing to name the attacker group. How do you answer?
basics
~20 sGive the executive the decisions they actually need rather than the name they asked for, and state what the evidence supports and what it does not. Assessments of who is responsible belong in a separate owned product, not a status briefing.
A desk head refuses to let you isolate a trading workstation with a live intruder on it. What now?
basics
~20 sNeither the SOC nor the desk head owns that call alone. Price both outcomes, escalate to the executive accountable for the firm's risk, offer a bounded watch with tripwires or a move to a spare workstation, and record who decided what and when.
The platform owner won't rebuild 291 servers you can't prove are clean — how do you declare eradication complete?
basics
~20 sStop claiming proof and state criteria instead: what was swept, what could not be, what compensates for the gap, and which named business owner accepts the remainder. Then run a time-boxed re-entry watch with specific tripwires and conditions that reopen the incident.
Your mass credential reset covers 4,000 accounts but the helpdesk can re-verify 400 a day. How do you scope it?
basics
~10 sRank the population by privilege and evidence of adversary use rather than resetting everyone equally, verify identity out-of-band, apply compensating controls to the un-reset tail, and have a named executive accept the residual exposure.
Your earliest logs aged out at 90 days and an executive wants one intrusion start date — what do you commit to?
basics
~20 sCommit to what the evidence supports: earliest observed activity with its date and citation, plus an explicit statement that the window before the retention edge cannot be assessed. Never convert an absence of records into a start date.
Counsel wants a suspected insider's account left live to gather evidence; the CISO wants it disabled now. Who decides?
basics
~20 sNeither function outranks the other, so the tie goes to the accountable executive the plan names, with HR present because cutting an employee's access is an employment act. Take the reversible option, time-box it, record the rationale.
Why is an intruder operating through your licensed RMM agent hard to contain by isolating one host?
basics
~20 sBecause the access path is the remote-management tenant, not the machine. The console can open a session on any enrolled host, and blocking the vendor's cloud at the perimeter cuts your own IT operations everywhere at once.
You notified on partial facts and the affected-record count later grew tenfold — how do you handle it?
basics
~10 sSupplement the original filing with the new figure and the analytic step that produced it. Growth explained by a widened search reads as diligence; growth contradicting an earlier assurance does not.
How do you tell 4,000 staff to stop using the company chat when the intruder is reading it?
basics
~20 sSend a short instruction that changes behaviour, carries no findings, and can be verified without clicking anything, through a path the adversary does not control. Write it assuming the intruder and the press both read it.
A foothold artefact predates your intrusion timeline by six months: how do you test it before moving patient zero back?
basics
~20 sTreat it as a hypothesis, not a finding. Test for positive linkage — shared unique artefacts, credentials, infrastructure — check continuity across the gap, and reconcile it against records of authorised activity before re-dating anything.
An extortion leak site lists your company with a 2.1 TB claim and a 72-hour timer — what does that prove?
basics
~20 sIt proves the actor published a claim and, if a sample is posted, possesses at least what is in that sample. The volume figure is unverified, the timer is a negotiating lever they set, and absence from the site would prove nothing.
A departing employee bulk-exported an HR dataset. Who must you consult before examining their HRIS audit trail?
basics
~20 sExamining a named employee's records needs HR as data owner, the privacy office for a documented lawful basis, counsel for the legal posture, and in several European jurisdictions consultation with the works council before behaviour-monitoring data is analysed.
Your post-intrusion collection requirement is refused on cost by the platform owner - what does the closure document record?
basics
~20 sRecord the requirement as raised, the refusal, who decided it and when, the exposure that remains in operational terms, any compensating measure you will actually perform, and a date to revisit. Never quietly delete the requirement.
Platform engineering auto-deletes flagged pods, so every intrusion loses its evidence - what do you negotiate?
basics
~20 sNot a veto on auto-remediation but a quarantine mode: replace the workload immediately, then hold the original with egress denied and credentials revoked for a hard-capped window, reaped automatically, invoked under standing authority by the incident lead.
Finance rejects the restore point that predates the intrusion — who owns that call and how do you frame it?
basics
~20 sThe trade is certain business loss against residual adversary presence, so the accountable business owner takes it, not the responder. Your job is to state honestly what each option costs, offer the middle paths, and record what was accepted.
The breached provider refuses to share the logs that would show whether its account touched your estate — what do you do?
basics
~20 sStop waiting for evidence you cannot compel. Set an explicit working assumption that the access was used, remediate on that basis, escalate commercially for narrow tenant-specific artefacts, and report the residual uncertainty plainly rather than as an all-clear.
A data owner disputes the classification label on tables an intruder read — how do you settle the intrusion's grade?
basics
~20 sGrade on what the columns actually contain, not only on the label. Hold the conservative grade as explicitly provisional, sample the real values from the columns the query records name, escalate to whoever is accountable for the label rather than to whoever disputes it, and record the basis.
Your cyber policy demands prompt notice and panel counsel, and only the CISO may declare — how do you make out-of-hours declaration workable?
basics
~20 sSplit the authority. Pre-delegate in writing to a named duty officer the right to declare and contain against a standing threshold, and keep the acts that bind the company on a pre-cleared path with named fallbacks.
showing 31–60 of 60