MCSE/MCSA Implementing and Administering Security in a Windows 2000 Network: Study Guide and DVD Training System (Exam 70-214)

Incident response is the process of identifying and then responding to a problem as it occurs. For the Microsoft exam, you need to know the underlying concepts behind incident response. In this section of the chapter, we look at all the underpinnings of incident response, chain of custody, and how to deal with a problem that occurs on a Microsoft-based network.

Defining an Incident Response Plan

Now that you know what an incident response plan is, you need to know why it is important. Problems will occur, and if an incident does crop up, you and your staff need to know how to deal with it appropriately. You should consider the following actions and incorporate them into your plan:

Note 

It is very important that you thoroughly test your incident response process before an incident occurs. Without thorough testing, you cannot be confident that the measures you have in place will be effective in responding to incidents.

Категории