CFS136 · Principles of Information Security

Chapter 14 Review: Incident Response and Forensics

A hands-on review station for the NIST incident response phases, digital forensics fundamentals, and the resilience metrics from Chapter 14.

Start Here

Five review stations, each a different way to practice Chapter 14. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.

What this chapter asked you to be able to do

  • Walk through the NIST SP 800-61 incident response process: preparation, detection and analysis, containment, eradication, recovery, and post-incident activity.
  • Match an action to the correct response phase and explain why it belongs there.
  • Explain digital forensics fundamentals: evidence acquisition, forensic images, hash verification, chain of custody, order of volatility, and live response.
  • Apply the order of volatility to decide which evidence to collect first.
  • Use resilience metrics such as RPO and RTO, backup strategies, recovery site types, and replication methods.

Your progress this session

These counters update as you check answers on each station. They reset when you reload the page.

0/20Terms viewed
0/8Phase matches correct
0/8Forensics matches correct
0/9Resilience matches correct
0/10Quiz correct
How to use each station Make a choice, then select Check to see whether it holds up and why. Every answer includes the reasoning, so a wrong pick is a chance to reread the logic rather than just the label. Keyboard users can move between tabs with the arrow keys.