CCSK Domain 9 Incident Response
hi welcome to ccsk domain nine this
domain is focused on incident response
life cycle in the
information security program there are
four questions that we can expect from
this domain in the exam this video will
help you to prepare for ccsk exam in the
lesser effort
and time watch till the end to avoid any
misconception
or any confusion if you are watching my
videos for the first time please
subscribe to the channel for the
regular videos updates before we deep
dive into the incident response uh
process uh let's take a look on the
event and
incidents uh how can we define that
any event is any observable
occurrence in the system or the network
there can be two different uh events one
is the regular events and
uh any adverse events so regular events
are all normal activities
um that we do on the computers
adverse events could be malware adverse
traffic
or tampering on the on your data
or on your services while on the
incident side any unplanned interruption
to the i.t services
or a reduction in the quality of service
is
an incident it is only adverse
and kind of phishing attack
dos attacks data breach is
um is in the category of
the adverse incidents
so all the incidents are events but
not all events are incidents so as i
mentioned
because events can be positive can be
negative
so all all events cannot be incident
because only adverse events are going to
be incident
as part of the incident response life
cycle
we have four different phases
preparation
uh detection and analysis containment
eradication and recovery and last is the
postmartem
so the incident response is very
important for
any information security program in any
organization most of the organizations
have
some sort of in incident response plan
to
govern how they will investigate an
attack but
as the cloud presents the distinct
differences
in both access to forensic data and
the governance the organization must
consider how their
incident response process will change in
the cloud
we will see uh in detail
how we can prepare for the
incident response program
so first of all if we begin with the
preparation phase uh we need to define a
process
of handling the incident response
who will be communicating and
facilitating um
this process and what will be the team
what what is the hardware and software
required to perform the incident
analysis
internal documentation we need to
document everything
related to all the ports that are open
serving in the infrastructure
all the services that are running inside
the infrastructure
we need to identify the assets um what
uh
and of course the classification of
their assets and
what is critical what is not and uh we
need to see
the network architecture or the layout
of our internal infrastructure training
identification
for our people evaluation of
infrastructure by scanning and
monitoring
vulnerability assessment and assess the
risks for
um for the infrastructure subscription
to the third party intelligence services
so if we do not have the internal
expertise on
threat intel then probably we will need
to see
that if we can subscribe to the third
party
services for threat intel
so how it impacts in the cloud so sla
and
the governance considerations
any incident that is using public cloud
or hosted
providers that require an
understanding of the service level
agreements and
likely the coordination with the cloud
provider
keep in mind that depending on your
relationship with the
provider you may not have direct contact
point and might be limited to
whatever is offered through the standard
support
so it is uh it has huge impact because
it is not
like the same that we have in
traditional infrastructure when we
prepare for the
uh incident response we we can have all
the contact points all the escalation
points
but in the cloud um it has dependency on
the cloud provider and we need to
carefully choose and we need to
you know consider these aspects in the
sla
and the governance infrastructure as a
service
platform as a service versus sas so in
in
in sas we
we we do not have much in control
because most of the things are being
managed
by the cloud provider directly and
we are highly dependent on um on the
cloud provider
uh we still have some space in um
infrastructure as a service and
something in uh
platform as a service which we can build
uh from the
infra from incident response point of
view
cloud jumpcade these are the tools that
are needed to
investigate in a remote location
especially um
for example when you have to collect the
logs and metadata for the forensics
you need to see
that what is the ability
that we have and how we can obtain
the different images and different stuff
from the cloud
especially from from from the cloud
provider
architect the cloud environment for
faster detection investigation and
response
enable the instrumentation such as the
cloud api and ensure that they feed to a
secure location
that's available to the investigators in
case of any incident
utilize the isolation to ensure that
attacks cannot
spread and compromise the entire
application use immutable servers when
possible
implement application stack map to
understand where the data is going to
reside in order to
factor in the geographic differences in
terms of monitoring and data capture
it can be very helpful to perform threat
modeling and table top exercise to
um to determine the most effective mean
of containment for the different type of
attacks on the different components in
the cloud stack
this should all include the differences
between responses for
infrastructure as a service platform as
a service and software as a service
detection and analysis phase alerts
all the network security monitoring host
monitoring
other indicators of the compromise um
all the
event monitoring uh we need to take care
um validate all the alerts
and escalate so we especially here we
need to uh
identify all the false positives and we
need to uh
reduce them um so that we are not
wasting our bandwidth or efforts in
unnecessary
alerts estimate the scope of incident
we need to estimate what is the
parameter of our
incident that we are going to cover
incident response um
yeah assign an incident manager who will
coordinate the further actions
it is important to assign an
incident manager responsibility of
communication designate a person who
will
communicate the incident containment and
recovery status to the higher management
build a timeline of the attack determine
the extent of the personal data loss
potential data loss notification and
coordination activities
so all these things will fall under a
detection analysis phase
which we need to take care so how it
impacts in the cloud uh
basically um the uh
some providers offers in cloud
monitoring and alert tool that
um kick off the automated incident
response activities
and uh the cloud platform uh
also offers the logging mechanisms uh
which can help to detect and analyze
um the incidents but you need to
implement the api as logging when
developing your own applications
especially
you cannot rely on the cloud provider in
that case
data source we need to see this is quite
different from
traditional i.t by the way in terms of
how to collect the data what all
methodologies that we need to consider
while collecting the data um one
challenge in collecting the information
may be
limited network visibility uh network
logs
from a cloud provider will tend to be
floor records
but not the full packet captures
forensic and investigation investigative
support um
always factor in what the cloud service
provider can provide
and whether it meets the chain of
custody requirements
not every incident will result in legal
action but it is important to consider
and to take the legal team's view
from the perspective of chain of custody
bit by bite copy may not be possible um
as you don't have the physical control
over the physical resources
so what we can do is snap shorting the
storage of virtual machines capturing
any metadata at the time of alert so
that the analysis can happen
based on that um if
your provider supports it pausing the vm
which will save the volatile memory
state
which will have to you know investigate
in forensics and
containment and eradication and recovery
containment taking the system offline
considerations for the data loss versus
service availability
ensuring the system don't destroy
themselves upon the detection
eradication and recovery clean up the
compromised
devices and restore system to the normal
operations
confirm the systems are functioning
properly
deploy controls to prevent the system
incidents
document everything about the incident
and gathering of the
evidences especially from the
perspective of chain of custody
cloud impact starting with the
management plane
meta structure it is very important
to to protect and to keep that free
you know free from the attackers
this will open involve invoking the
break glass procedure
for example just like when you break the
glasses of
the the rack in a physical data center
and you have access to the all the
physical resources
lying there similarly if you have root
access or the the admin access to the
resources which are there in the
management plane
it has a similar similar thing and it is
very important to protect it
from the attackers
more flexible um this phase is more
flexible
in the cloud as the resources can be
rebuilt quickly from the scratch
thanks to software defined
infrastructure
service model for sas and some pass you
have to rely on the providers hence have
some limitations here
post martem this is the last phase of
the incident response
phase um we
in this phase what we check is what
could have been done better
could the attack have been detected
sooner
or what additional data would have been
helpful to isolate the attack
faster does the incident response
process need to change
if so then what can be done better so
basically
these these are the questions which we
need to retrospect with the
incident response team to improve the
process
and for the continuous improvement
so how does it impact uh in terms of the
cloud
pay particular attention to the
limitation in the data
collected and figure out how to address
the issues moving forward
it is hard to change the slas especially
if you find
something or some areas which requires
the improvement
it is really hard to you know to change
the sla at that time
but if you find any loophole or any
uh gaps which are not aligned with the
slas previously
agreed slas and the contracts then of
course
this opens up the opportunity to
renegotiate the
the contracts and the sla with the
provider
let's take a look on some questions here
which phase of the incident response
life cycle is used to determine
ways to improve the incident response
process
so i think this talks about the
improvement here
the containment eradication recovery it
is not the area
um where we discuss about the
improvement preparation is the first
phase where we prepare for
the incident response detection and
analysis
is the second phase where we
prepare for and deploy the
the detection tools and perform the
analysis
in that postmodern is the phase when we
talk about the improvement and we do the
retrospect
with the team so this is the right
answer
uh next is a customer should design the
cloud
environment in a way that optimizes the
effectiveness of incident response
this includes all of the following
measures except use
immutable servers if possible
this is quite in line with the cloud
design
enable api logging to an external
secure location this is also in line as
we discussed in the slides
um insure contract include 100
uptime guarantee uh i
doubt here utilize isolation to limit
the potential negative impact
um this is this is
where i think c is um
i never seen anything as part of the
contract which is 100 percent
uptime so usually what we talk about in
the five nines
uptime let's say 99.999 so this is the
five nines
and uh based on that you may have seven
nines or nine nines
uptime but it is never been a hundred
percent
so this is the uh right answer here
um next is to add in uh
getting information about the potential
attackers
the cloud customer might consider
um sending undercover
operatives into the non-attack hangout
paying known attackers for insight into
their operations
um offering a bounty to anyone
who will attack the attacker
subscribing to an external
threat intelligence service so this is
the thing i think we discussed in the
preparation phase
that if you do not have the internal
expertise
who can do on the threat intel then
it is a good idea to subscribe for the
external threat intelligence service
so this is the right answer here
next is in order to determine whether
log data received from a cloud provider
satisfies a chain of custody requirement
the security practitioners should
consult
their supervisors they cannot help with
chain of custody
senior management they cannot um
attorneys
uh this is legal yes cloud providers
no so i don't know i i think chain of
custody is pretty much
so this is the key word here chain of
custody because this is the legal
requirement and can only be discussed or
verified
with the help of attorneys so it should
always be discussed
should always be consulted with the
attorneys here
thanks for watching the full video with
this we conclude ccsk domain 9
incident response um
i hope you liked the video please
subscribe like comment and share in your
network so that
others can take the benefit thank you
More transcripts
Explore other videos transcribed with YouTLDR.

Top Down Analysis Isn't Hard, It's Misunderstood
Waqar Asim · English

BIÓLOGO HENRIQUE - ENCANTADOR DE SERPENTE - PODCAST 3 IRMÃOS #687
Podcast 3 irmãos · English

一次搞懂!香檳不是唯一的氣泡酒?一段片看懂3大產區風味
酒言酒語 Great Wines Think Alike · English

2024 Maruti Suzuki Swift review - Return to form for India’s favourite hatchback | @autocarindia1
Autocar India · Hindi

Carta de un bebe desde el vientre de su mama
Luigi C · Spanish

💍 حمود الخضر - زفّة فرحة أبوها
Humood AlKhudher حمود الخضر · Arabic

قصص سورة الكهف
الشيخ(المهندس) | محمد المقرمي · English

Video Animasi Matematika | Barisan Aritmatika
Jose Abdalah · English

Secret To Getting Better At Talking To People
Improvement Pill · English

The Difference Between Quality Assurance and Quality Control
QualityEngineers Guide · English

📚 Present vs Past Tense | Easy English Sentences for Beginners
Easy English with Fi · English

5 Minutes Daily English Practice | Speak English Fluently Fast ✅ | Learn English Through Podcast 🎧
learn English · English
Get the TLDR of any YouTube video
Transcribe, summarize, and repurpose videos in 125+ languages — free, no signup required.