Chương 4 / 524% của kỳ thi

Security Operations and Incident Response

This chapter focuses on running security day to day: detecting threats, responding to incidents, and recovering from disruption. You will learn the incident response lifecycle, monitoring tools like SIEM and EDR, hardening and patching, digital forensics, and resilience metrics. Effective operations turn prevention into detection and recovery when prevention fails.

Incident Response Lifecycle

A structured process ensures incidents are handled consistently and lessons feed back into improvement. Each phase has a distinct goal, from readiness through post-incident review.

Preparation
Build plans, tools, and trained teams before an incident so response is fast and coordinated.
Detection and analysis
Identify and scope the incident using alerts, logs, and correlation to understand what happened.
Containment
Isolate affected systems to stop spread while preserving evidence for investigation.
Eradication and recovery
Remove the threat, then restore systems to normal and verify they are clean.
Lessons learned
Review the incident to improve controls, plans, and future response.

Monitoring and Detection

Continuous monitoring surfaces threats that slip past preventive controls. Centralized visibility and automation let small teams handle large volumes of activity.

SIEM
Aggregates and correlates logs from many sources to detect and investigate security events.
IDS and IPS
An IDS alerts on malicious traffic; an IPS sits inline and can block it automatically.
EDR
Records endpoint activity and enables investigation and automated response to host threats.
Detection methods
Signature-based matches known patterns; anomaly-based flags deviations from a baseline to catch novel attacks.
SOAR
Automates and orchestrates response with playbooks, reducing analyst workload and response time.

Hardening, Patching, and Forensics

Reducing attack surface and handling evidence properly are core operational duties. Disciplined patching closes known holes, while forensics preserves evidence for investigations.

Hardening
Disable unneeded services and apply secure baselines to shrink the attack surface.
Patch management
Test and deploy vendor updates promptly to remediate known vulnerabilities.
Chain of custody
Document every handler and transfer of evidence so it remains admissible.
Forensic imaging
Hash originals and images to prove evidence was not altered during acquisition.
Secure disposal
Use degaussing or physical destruction to make data on retired media unrecoverable.

Resilience, Recovery, and Assessment

Operations also plan for disruption and validate defenses proactively. Recovery metrics and testing ensure the organization can withstand and bounce back from incidents.

Backups
Full, differential, and incremental strategies balance restore speed and storage; keep offline copies.
RTO and RPO
RTO is the maximum tolerable downtime; RPO is the maximum tolerable data loss in time.
Recovery sites
Hot sites recover fastest at highest cost; cold sites are cheap but slow to activate.
Vulnerability scanning and pen testing
Scans find known weaknesses without exploiting them; pen tests actively exploit to prove real risk.
Exercises
Tabletop and technical drills validate plans and reveal gaps before a real incident.
Kiểm tra kiến thức của bạn
Câu hỏi luyện tập về Security Operations and Incident Response
Luyện tập ngay →

Last updated: July 2026

Báo lỗi