7. Security Operations Flashcards

1
Q

Define an event.

A

An observable change in state

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define an alert.

A

Flagged events that may require further investigation to determine if an incident has taken place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define an incident.

A

Adverse impact to the system or network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 3 types of attacks?

A
  1. Dos/DDoS
  2. Malicious code
  3. Inappropriate usage
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the four steps of incident control?

A
  1. Preparation
  2. Detection
  3. Containment
  4. Post-incident review
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an incident with an unknown cause referred to as?

A

A problem

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the defined steps of problem management?

A
  1. Incident notification
  2. Root cause analysis
  3. Solution determination
  4. Request for change
  5. Implement solution
  6. Monitor and report
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 7 steps of the forensic investigation process?

A
  1. Identification
  2. Preservation
  3. Collection
  4. Examination
  5. Analysis
  6. Presentation
  7. Decision
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Define Direct evidence

A

Can prove a fact by itself and does not need back up information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Define Real evidence

A

Physical evidence. The objects themselves that are used in a crime.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define best evidence

A

Most reliable. i.e. a signed contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define secondary evidence

A

Not strong enough to stand alone, but can support other evidence. I.e. an expert opinion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define corroborative evidence

A

Support evidence, backs up other information presented. Cannot stand on its own.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Define circumstantial

A

Proves one fact which can be used to reasonably suggest another. Cannot stand on its own.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Who should conduct investigations?

A

Usually the FBI or Secret Service. You must be careful about 4th amendment rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does RAID 0 mean?

A

Stripping across different drives

17
Q

What does RAID 1 mean?

A

Mirroring one drive to another, for redundancy.

18
Q

What does RAID 5 mean?

A

Stripping across hard drives with parity.

19
Q

Define Server clustering

A

A group of servers that are managed as a single system. Not all clusters do load balancing.

20
Q

What should you always check with performing an unscheduled backup?

A

Make sure it is a copy!

21
Q

Define a Copy Backup

A

Same as a full back up, but Archive Bit is not reset.

22
Q

Define a full backup

A

Back up EVERYTHING. Archival but is reset.

23
Q

Define Incremental back up

A

Back up all files that have been modified since last back up. Archive bit is reset.

24
Q

Define differential backup

A

Backs up all files that have been modified since last full back up. Archive but is not reset.

25
Q

Define disk shadowing

A

A type of database backup. Mirroring technology that can update one or more copies of data at the same time.

Data saved to two different media types for redundancy.

26
Q

Define electric vaulting

A

A type of database back up.

Copy of modified file is sent to a remote location where an original back up is stored.

Transfers bulk backup information.

27
Q

Define remote journaling

A

A type of data base back up

Moves the journal or transaction log to a remote location, not the actual files.