Full Transcript

·YouTLDR

CCSK Domain 9 Incident Response

18:18EnglishTranscribed Jul 25, 2026
0:01

hi welcome to ccsk domain nine this

0:03

domain is focused on incident response

0:05

life cycle in the

0:06

information security program there are

0:08

four questions that we can expect from

0:11

this domain in the exam this video will

0:14

help you to prepare for ccsk exam in the

0:16

lesser effort

0:17

and time watch till the end to avoid any

0:20

misconception

0:21

or any confusion if you are watching my

0:23

videos for the first time please

0:24

subscribe to the channel for the

0:26

regular videos updates before we deep

0:29

dive into the incident response uh

0:32

process uh let's take a look on the

0:35

event and

0:36

incidents uh how can we define that

0:39

any event is any observable

0:42

occurrence in the system or the network

0:46

there can be two different uh events one

0:48

is the regular events and

0:50

uh any adverse events so regular events

0:53

are all normal activities

0:55

um that we do on the computers

0:58

adverse events could be malware adverse

1:02

traffic

1:03

or tampering on the on your data

1:06

or on your services while on the

1:09

incident side any unplanned interruption

1:13

to the i.t services

1:14

or a reduction in the quality of service

1:17

is

1:17

an incident it is only adverse

1:22

and kind of phishing attack

1:25

dos attacks data breach is

1:28

um is in the category of

1:32

the adverse incidents

1:36

so all the incidents are events but

1:39

not all events are incidents so as i

1:42

mentioned

1:43

because events can be positive can be

1:45

negative

1:48

so all all events cannot be incident

1:52

because only adverse events are going to

1:54

be incident

1:57

as part of the incident response life

2:00

cycle

2:01

we have four different phases

2:04

preparation

2:05

uh detection and analysis containment

2:08

eradication and recovery and last is the

2:12

postmartem

2:13

so the incident response is very

2:16

important for

2:17

any information security program in any

2:19

organization most of the organizations

2:21

have

2:22

some sort of in incident response plan

2:25

to

2:25

govern how they will investigate an

2:27

attack but

2:29

as the cloud presents the distinct

2:31

differences

2:32

in both access to forensic data and

2:36

the governance the organization must

2:38

consider how their

2:40

incident response process will change in

2:42

the cloud

2:45

we will see uh in detail

2:48

how we can prepare for the

2:51

incident response program

2:55

so first of all if we begin with the

2:58

preparation phase uh we need to define a

3:00

process

3:01

of handling the incident response

3:05

who will be communicating and

3:06

facilitating um

3:08

this process and what will be the team

3:13

what what is the hardware and software

3:15

required to perform the incident

3:18

analysis

3:21

internal documentation we need to

3:23

document everything

3:25

related to all the ports that are open

3:28

serving in the infrastructure

3:30

all the services that are running inside

3:33

the infrastructure

3:34

we need to identify the assets um what

3:37

uh

3:38

and of course the classification of

3:40

their assets and

3:41

what is critical what is not and uh we

3:44

need to see

3:45

the network architecture or the layout

3:48

of our internal infrastructure training

3:51

identification

3:53

for our people evaluation of

3:56

infrastructure by scanning and

3:57

monitoring

3:58

vulnerability assessment and assess the

4:00

risks for

4:02

um for the infrastructure subscription

4:05

to the third party intelligence services

4:07

so if we do not have the internal

4:09

expertise on

4:10

threat intel then probably we will need

4:12

to see

4:15

that if we can subscribe to the third

4:17

party

4:18

services for threat intel

4:22

so how it impacts in the cloud so sla

4:25

and

4:26

the governance considerations

4:30

any incident that is using public cloud

4:33

or hosted

4:34

providers that require an

4:37

understanding of the service level

4:39

agreements and

4:40

likely the coordination with the cloud

4:43

provider

4:44

keep in mind that depending on your

4:46

relationship with the

4:48

provider you may not have direct contact

4:52

point and might be limited to

4:55

whatever is offered through the standard

4:57

support

4:58

so it is uh it has huge impact because

5:02

it is not

5:03

like the same that we have in

5:06

traditional infrastructure when we

5:09

prepare for the

5:11

uh incident response we we can have all

5:14

the contact points all the escalation

5:16

points

5:17

but in the cloud um it has dependency on

5:20

the cloud provider and we need to

5:22

carefully choose and we need to

5:26

you know consider these aspects in the

5:29

sla

5:29

and the governance infrastructure as a

5:33

service

5:34

platform as a service versus sas so in

5:37

in

5:39

in sas we

5:42

we we do not have much in control

5:45

because most of the things are being

5:47

managed

5:48

by the cloud provider directly and

5:51

we are highly dependent on um on the

5:54

cloud provider

5:55

uh we still have some space in um

5:58

infrastructure as a service and

5:59

something in uh

6:00

platform as a service which we can build

6:02

uh from the

6:03

infra from incident response point of

6:06

view

6:07

cloud jumpcade these are the tools that

6:10

are needed to

6:11

investigate in a remote location

6:14

especially um

6:15

for example when you have to collect the

6:17

logs and metadata for the forensics

6:21

you need to see

6:24

that what is the ability

6:28

that we have and how we can obtain

6:31

the different images and different stuff

6:34

from the cloud

6:36

especially from from from the cloud

6:39

provider

6:41

architect the cloud environment for

6:45

faster detection investigation and

6:47

response

6:49

enable the instrumentation such as the

6:52

cloud api and ensure that they feed to a

6:57

secure location

6:59

that's available to the investigators in

7:01

case of any incident

7:03

utilize the isolation to ensure that

7:06

attacks cannot

7:07

spread and compromise the entire

7:09

application use immutable servers when

7:11

possible

7:13

implement application stack map to

7:16

understand where the data is going to

7:18

reside in order to

7:19

factor in the geographic differences in

7:21

terms of monitoring and data capture

7:23

it can be very helpful to perform threat

7:25

modeling and table top exercise to

7:28

um to determine the most effective mean

7:31

of containment for the different type of

7:33

attacks on the different components in

7:35

the cloud stack

7:38

this should all include the differences

7:40

between responses for

7:41

infrastructure as a service platform as

7:43

a service and software as a service

7:48

detection and analysis phase alerts

7:51

all the network security monitoring host

7:54

monitoring

7:56

other indicators of the compromise um

7:59

all the

8:00

event monitoring uh we need to take care

8:03

um validate all the alerts

8:06

and escalate so we especially here we

8:09

need to uh

8:10

identify all the false positives and we

8:12

need to uh

8:13

reduce them um so that we are not

8:16

wasting our bandwidth or efforts in

8:18

unnecessary

8:20

alerts estimate the scope of incident

8:24

we need to estimate what is the

8:26

parameter of our

8:28

incident that we are going to cover

8:29

incident response um

8:31

yeah assign an incident manager who will

8:35

coordinate the further actions

8:37

it is important to assign an

8:40

incident manager responsibility of

8:42

communication designate a person who

8:44

will

8:44

communicate the incident containment and

8:46

recovery status to the higher management

8:49

build a timeline of the attack determine

8:51

the extent of the personal data loss

8:54

potential data loss notification and

8:56

coordination activities

8:58

so all these things will fall under a

9:00

detection analysis phase

9:03

which we need to take care so how it

9:05

impacts in the cloud uh

9:08

basically um the uh

9:11

some providers offers in cloud

9:13

monitoring and alert tool that

9:14

um kick off the automated incident

9:17

response activities

9:19

and uh the cloud platform uh

9:22

also offers the logging mechanisms uh

9:24

which can help to detect and analyze

9:27

um the incidents but you need to

9:29

implement the api as logging when

9:31

developing your own applications

9:32

especially

9:33

you cannot rely on the cloud provider in

9:35

that case

9:37

data source we need to see this is quite

9:40

different from

9:41

traditional i.t by the way in terms of

9:45

how to collect the data what all

9:48

methodologies that we need to consider

9:50

while collecting the data um one

9:53

challenge in collecting the information

9:54

may be

9:55

limited network visibility uh network

9:57

logs

9:58

from a cloud provider will tend to be

10:01

floor records

10:03

but not the full packet captures

10:07

forensic and investigation investigative

10:09

support um

10:10

always factor in what the cloud service

10:12

provider can provide

10:14

and whether it meets the chain of

10:16

custody requirements

10:18

not every incident will result in legal

10:20

action but it is important to consider

10:23

and to take the legal team's view

10:27

from the perspective of chain of custody

10:30

bit by bite copy may not be possible um

10:33

as you don't have the physical control

10:35

over the physical resources

10:37

so what we can do is snap shorting the

10:39

storage of virtual machines capturing

10:42

any metadata at the time of alert so

10:44

that the analysis can happen

10:46

based on that um if

10:49

your provider supports it pausing the vm

10:53

which will save the volatile memory

10:54

state

10:55

which will have to you know investigate

10:58

in forensics and

11:02

containment and eradication and recovery

11:06

containment taking the system offline

11:11

considerations for the data loss versus

11:13

service availability

11:15

ensuring the system don't destroy

11:17

themselves upon the detection

11:19

eradication and recovery clean up the

11:22

compromised

11:23

devices and restore system to the normal

11:25

operations

11:26

confirm the systems are functioning

11:28

properly

11:30

deploy controls to prevent the system

11:33

incidents

11:35

document everything about the incident

11:37

and gathering of the

11:38

evidences especially from the

11:39

perspective of chain of custody

11:43

cloud impact starting with the

11:45

management plane

11:48

meta structure it is very important

11:51

to to protect and to keep that free

11:54

you know free from the attackers

11:58

this will open involve invoking the

12:00

break glass procedure

12:02

for example just like when you break the

12:05

glasses of

12:06

the the rack in a physical data center

12:09

and you have access to the all the

12:11

physical resources

12:12

lying there similarly if you have root

12:15

access or the the admin access to the

12:17

resources which are there in the

12:19

management plane

12:20

it has a similar similar thing and it is

12:23

very important to protect it

12:24

from the attackers

12:28

more flexible um this phase is more

12:30

flexible

12:31

in the cloud as the resources can be

12:32

rebuilt quickly from the scratch

12:34

thanks to software defined

12:36

infrastructure

12:38

service model for sas and some pass you

12:41

have to rely on the providers hence have

12:44

some limitations here

12:46

post martem this is the last phase of

12:48

the incident response

12:50

phase um we

12:54

in this phase what we check is what

12:56

could have been done better

12:58

could the attack have been detected

13:00

sooner

13:01

or what additional data would have been

13:03

helpful to isolate the attack

13:04

faster does the incident response

13:07

process need to change

13:09

if so then what can be done better so

13:12

basically

13:12

these these are the questions which we

13:14

need to retrospect with the

13:17

incident response team to improve the

13:20

process

13:20

and for the continuous improvement

13:24

so how does it impact uh in terms of the

13:27

cloud

13:28

pay particular attention to the

13:30

limitation in the data

13:32

collected and figure out how to address

13:36

the issues moving forward

13:37

it is hard to change the slas especially

13:40

if you find

13:42

something or some areas which requires

13:45

the improvement

13:46

it is really hard to you know to change

13:49

the sla at that time

13:50

but if you find any loophole or any

13:54

uh gaps which are not aligned with the

13:57

slas previously

13:58

agreed slas and the contracts then of

14:01

course

14:02

this opens up the opportunity to

14:03

renegotiate the

14:07

the contracts and the sla with the

14:09

provider

14:13

let's take a look on some questions here

14:16

which phase of the incident response

14:18

life cycle is used to determine

14:20

ways to improve the incident response

14:23

process

14:23

so i think this talks about the

14:26

improvement here

14:29

the containment eradication recovery it

14:31

is not the area

14:32

um where we discuss about the

14:34

improvement preparation is the first

14:36

phase where we prepare for

14:38

the incident response detection and

14:40

analysis

14:41

is the second phase where we

14:44

prepare for and deploy the

14:48

the detection tools and perform the

14:50

analysis

14:51

in that postmodern is the phase when we

14:54

talk about the improvement and we do the

14:56

retrospect

14:57

with the team so this is the right

14:59

answer

15:00

uh next is a customer should design the

15:03

cloud

15:04

environment in a way that optimizes the

15:08

effectiveness of incident response

15:11

this includes all of the following

15:15

measures except use

15:18

immutable servers if possible

15:21

this is quite in line with the cloud

15:24

design

15:25

enable api logging to an external

15:28

secure location this is also in line as

15:31

we discussed in the slides

15:34

um insure contract include 100

15:38

uptime guarantee uh i

15:42

doubt here utilize isolation to limit

15:45

the potential negative impact

15:48

um this is this is

15:51

where i think c is um

15:54

i never seen anything as part of the

15:57

contract which is 100 percent

15:58

uptime so usually what we talk about in

16:01

the five nines

16:02

uptime let's say 99.999 so this is the

16:07

five nines

16:08

and uh based on that you may have seven

16:10

nines or nine nines

16:12

uptime but it is never been a hundred

16:15

percent

16:16

so this is the uh right answer here

16:20

um next is to add in uh

16:23

getting information about the potential

16:26

attackers

16:27

the cloud customer might consider

16:30

um sending undercover

16:34

operatives into the non-attack hangout

16:37

paying known attackers for insight into

16:40

their operations

16:42

um offering a bounty to anyone

16:47

who will attack the attacker

16:50

subscribing to an external

16:54

threat intelligence service so this is

16:56

the thing i think we discussed in the

16:58

preparation phase

17:00

that if you do not have the internal

17:02

expertise

17:03

who can do on the threat intel then

17:07

it is a good idea to subscribe for the

17:10

external threat intelligence service

17:12

so this is the right answer here

17:15

next is in order to determine whether

17:18

log data received from a cloud provider

17:21

satisfies a chain of custody requirement

17:24

the security practitioners should

17:27

consult

17:28

their supervisors they cannot help with

17:31

chain of custody

17:32

senior management they cannot um

17:35

attorneys

17:36

uh this is legal yes cloud providers

17:39

no so i don't know i i think chain of

17:42

custody is pretty much

17:43

so this is the key word here chain of

17:45

custody because this is the legal

17:47

requirement and can only be discussed or

17:50

verified

17:52

with the help of attorneys so it should

17:54

always be discussed

17:56

should always be consulted with the

17:57

attorneys here

18:00

thanks for watching the full video with

18:02

this we conclude ccsk domain 9

18:05

incident response um

18:08

i hope you liked the video please

18:09

subscribe like comment and share in your

18:11

network so that

18:12

others can take the benefit thank you

More transcripts

Explore other videos transcribed with YouTLDR.

Get the TLDR of any YouTube video

Transcribe, summarize, and repurpose videos in 125+ languages — free, no signup required.

Try YouTLDR Free