Escalation chapter quiz
Escalation chapter quiz
No grades. The point is to push your thinking. Tap an option to see if it lands.
Mid-investigation, the evidence confirms one canonical escalation criterion, but the analyst feels the case would be stronger after finishing the remaining phases. What should they do?
Pre-defined criteria exist precisely to remove this judgment call under pressure. One confirmed criterion escalates the case, from whatever phase the investigation is in, and the packet finishes in parallel. Overriding the default requires documented reasoning, not a feeling that more polish would help.
What is the difference between event triage and incident response?
The distinction is about the question being asked. Triage is 'what is going on.' IR is 'what do we do about it.' Conflating them leads to premature escalation or stalled investigations.
The handoff packet should be optimized for...
The packet is the bridge between triage and IR. The metric is whether the next tier can act without asking the triage analyst to re-explain. Brevity is good; completeness is the goal.
A handoff packet has all nine sections filled in. What does the methodology still require before it is declared ready?
Completeness is structural; actionability is functional, and a complete packet can still fail it. The case summary plus Risk verdict should orient the receiving tier in under five minutes. The packet should tee up the specific decision the next tier must make ('isolate the second host', 'engage compliance'), not just describe the case. And an analyst with no prior context should be able to continue the work without the author in the room. The practical check for that last test: hand the packet to an uninvolved peer, and if they cannot state the verdict in one sentence after five minutes, it is not done.
In the three-tier SOC model, where is the decision usually made that a case becomes a declared incident?
Need a nudge?
Meets-a-criterion and is-an-incident are two different bars.
Tier 1 receives and validates alerts, closes false-positives with detection feedback, and usually carries the Alert, Subject, and Scope work; meeting an escalation criterion moves the case up, but that is escalation, not declaration. Tier 2 brings the specialized investigation depth (Uncover and Risk usually complete here) and holds the decision on whether the case becomes a declared incident. Tier 3 is the senior technical bench for the cases Tier 2 cannot close; the cross-functional response (incident command, legal, communications, executives) is a separate function that activates once an incident is declared, not a tier. The bar for 'escalate' and the bar for 'declared incident' are different, and keeping them separate is what the tier boundaries encode.
When does law enforcement get engaged?
Law enforcement is one external path among several. Engagement is selective (specific case types), channeled through legal counsel, and not a default for every incident.
The terms 'event', 'alert', and 'incident' get used interchangeably in casual conversation. How does ASSURED distinguish them?
ASSURED treats them as distinct concepts with distinct operational meaning. Events are raw observability data. Alerts cross a threshold and become SOC work. An incident is a violation, or imminent threat of violation, of security policy or standard security practice (NIST SP 800-61), typically confirmed out of one or more alerts and requiring coordinated response. Conflating them loses precision under pressure.
Uncover confirms lateral movement into systems outside the original Scope boundary. What is the right escalation behavior?
Confirmed lateral movement is one of the four canonical criteria, and the break-glass rule fires the moment a criterion is confirmed, from any phase. A spreading compromise is IR's problem to contain while investigation continues. The dynamic loop still matters: refining Scope and re-running Uncover is exactly the scoping support IR needs next, but it happens in parallel under IR's clock, not as a precondition for escalating. Deferring escalation through a full loop iteration while a compromise spreads is the failure mode the criteria exist to prevent.
Risk returns a defensible low-residual-risk verdict on a suspicious-binary case. What does the Escalation phase produce?
Escalation still runs; the outcome is a documented close instead of a transfer. The worked example checks five closure criteria (no confirmed malicious activity, no impact to business-critical systems, no lateral movement, no persistence or credential access, residual risk explicitly bounded), each backed by Uncover findings. Notifications are quiet and targeted: the SOC manager for shift visibility, detection engineering with the rule-tuning ticket, nobody else, because loud notices for a documented false-positive train the team to discount future ones. The closure record is built on the nine handoff-packet sections. The close is arguably the harder discipline, since the analyst is asking a future reader to trust the absence of compromise.
Your handoff packet has eight strong sections, but you noticed during the case that you forgot to log the 14:02 page to your SOC manager. What is the right call?
The Communication record is the ninth section of the handoff packet for exactly this reason. Backfilling notifications (who, on which channel, when) with real timestamps prevents duplicate pages, gives IR an instant view of who already knows, and starts the audit trail before memory fades. Verbal handoffs and post-close amendments both lose information.