CPA Exam Lab
Section 2: 35–45%I10

Incident Response and Security Monitoring

Exam insight

When a breach occurs, the exam expects you to know the incident response lifecycle in order and to recognize the monitoring tools that detect events. Understanding logging, SIEM, IDS/IPS, forensics, chain of custody, and breach notification ties the whole security program together.

What AICPA wants you to know

  • 1List the phases of the incident response lifecycle in order.
  • 2Explain the role of logging and centralized monitoring.
  • 3Describe what a SIEM does and how it aids detection.
  • 4Distinguish an IDS from an IPS.
  • 5Explain digital forensics and the importance of chain of custody.
  • 6Summarize breach notification obligations at a high level.

Exam tip

Study smarter: before you expand each card, cover the screen and try to recall what the concept means from its title alone. Retrieving it from memory builds the recall the exam actually tests, and it beats re-reading.