CIS 359 STUDY Great Stories/cis359study.com CIS 359 STUDY Great Stories/cis359study.com | Page 38

____ is the process of systematically examining information assets for evidentiary material that can provide insight into how an incident transpired. Question 39 A favorite pastime of information security professionals is ____, which is a simulation of attack and defense activities using realistic networks and information systems. Question 40 Should an incident begin to escalate, the CSIRT team leader continues to add resources and skill sets as necessary to attempt to contain and terminate the incident. The resulting team is called the ____ for this particular incident. Question 41 General users require training on the technical details of how to do their jobs securely, including good security practices, ____ management, specialized access controls, and violation reporting.