7. Security Operations Flashcards

(27 cards)

1
Q

Define an event.

A

An observable change in state

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define an alert.

A

Flagged events that may require further investigation to determine if an incident has taken place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define an incident.

A

Adverse impact to the system or network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 3 types of attacks?

A
  1. Dos/DDoS
  2. Malicious code
  3. Inappropriate usage
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the four steps of incident control?

A
  1. Preparation
  2. Detection
  3. Containment
  4. Post-incident review
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an incident with an unknown cause referred to as?

A

A problem

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the defined steps of problem management?

A
  1. Incident notification
  2. Root cause analysis
  3. Solution determination
  4. Request for change
  5. Implement solution
  6. Monitor and report
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 7 steps of the forensic investigation process?

A
  1. Identification
  2. Preservation
  3. Collection
  4. Examination
  5. Analysis
  6. Presentation
  7. Decision
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Define Direct evidence

A

Can prove a fact by itself and does not need back up information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Define Real evidence

A

Physical evidence. The objects themselves that are used in a crime.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define best evidence

A

Most reliable. i.e. a signed contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define secondary evidence

A

Not strong enough to stand alone, but can support other evidence. I.e. an expert opinion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define corroborative evidence

A

Support evidence, backs up other information presented. Cannot stand on its own.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Define circumstantial

A

Proves one fact which can be used to reasonably suggest another. Cannot stand on its own.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Who should conduct investigations?

A

Usually the FBI or Secret Service. You must be careful about 4th amendment rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does RAID 0 mean?

A

Stripping across different drives

17
Q

What does RAID 1 mean?

A

Mirroring one drive to another, for redundancy.

18
Q

What does RAID 5 mean?

A

Stripping across hard drives with parity.

19
Q

Define Server clustering

A

A group of servers that are managed as a single system. Not all clusters do load balancing.

20
Q

What should you always check with performing an unscheduled backup?

A

Make sure it is a copy!

21
Q

Define a Copy Backup

A

Same as a full back up, but Archive Bit is not reset.

22
Q

Define a full backup

A

Back up EVERYTHING. Archival but is reset.

23
Q

Define Incremental back up

A

Back up all files that have been modified since last back up. Archive bit is reset.

24
Q

Define differential backup

A

Backs up all files that have been modified since last full back up. Archive but is not reset.

25
Define disk shadowing
A type of database backup. Mirroring technology that can update one or more copies of data at the same time. Data saved to two different media types for redundancy.
26
Define electric vaulting
A type of database back up. Copy of modified file is sent to a remote location where an original back up is stored. Transfers bulk backup information.
27
Define remote journaling
A type of data base back up Moves the journal or transaction log to a remote location, not the actual files.