Skip to main content

Quiz

Defend detection objectives, telemetry trust, rule validation, triage, severity, timelines, evidence preservation, forensic hypotheses, incident command, containment, eradication, revocation, recovery, post-incident learning, architecture principles, fitness functions, zero trust, review evidence, purple teaming, disclosure, and executive risk decisions.

Required evidence

Submit threat-linked rules, validated telemetry, replay and noise results, evidence provenance, timeline, decision log, containment and recovery proof, architecture correction, independent finding disposition, and residual risk. Protect sensitive incident data.

Oral defense

Triage one ambiguous signal, distinguish evidence from inference, demonstrate containment and trusted recovery, and defend the architecture or executive risk decision.

Source backbone

Use NIST SP 800-61, MITRE ATT&CK, NIST CSF, and Building Secure and Reliable Systems.