Section 2: 35–45%I10
Incident Response and Security Monitoring
Exam insight
When a breach occurs, the exam expects you to know the incident response lifecycle in order and to recognize the monitoring tools that detect events. Understanding logging, SIEM, IDS/IPS, forensics, chain of custody, and breach notification ties the whole security program together.
What AICPA wants you to know
- 1List the phases of the incident response lifecycle in order.
- 2Explain the role of logging and centralized monitoring.
- 3Describe what a SIEM does and how it aids detection.
- 4Distinguish an IDS from an IPS.
- 5Explain digital forensics and the importance of chain of custody.
- 6Summarize breach notification obligations at a high level.
Patterns in this topic
The exam re-skins the same archetypes. Recognize these here, then drill them in the Pattern Lab.
The Incident PlaybookRun the incident lifecycle in order: detect, contain, eradicate, recover, then learn, and keep the forensic chain of custody intact.The Privacy GuardPrivacy is about personal data specifically: de-identify by the right method, apply the right regime, and start the breach clock on time.
Exam tip
Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.