Documentation chapter quiz

Quiz

Documentation chapter quiz

No grades. The point is to push your thinking. Tap an option to see if it lands.

When should documentation be written?

Which is the biggest documentation pitfall?

What is the test of good documentation?

A closed false-positive case is documented. What is its main downstream use?

An investigation checked for persistence mechanisms and found none. Under time pressure, the analyst leaves that check out of the record, reasoning that there was nothing to report. What went wrong?

An analyst pulls a suspicious binary off a host into a personal scratch directory while working the case, then uploads it to the case-management system at close. What happened to the artifact?

Need a nudge?

What can the analyst prove about the file's history during the scratch-directory stretch?

A closure record includes full log excerpts containing customer PII, on the reasoning that the excerpts are the evidence. What does the standard say?

A record reads: 'PowerShell spawned from winword.exe at 09:11 UTC, indicating macro-based initial access.' What does the clarity standard say about this sentence?

A closed case record contains a flawless technical timeline and nothing else. Who is left unserved?

When in the lifecycle should Documentation begin?

Next up

Methodology complete

See the closure