Domain 7, Security Operations Flashcards
BCP
Business continuity Plan. Long term plan to ensure the continuity of business ops.
Collusion
agreement between 2+ individuals to subvert sec system.
Continuity of Operations Plan - COOP
Plan to maintain ops during a disaster.
Disaster
Disruptive event that interrupts normal system operations
Disaster recovery plan DRP
Short term plan to recover from a disruptive event.
MTBF
Mean time between failures
MTTR
Mean time to repair/recover
Mirroring
RAID - Duplication of data to another disk
RAID
Redundant array of inexpensive disks
Striping
Spread data across multiple disks.
Slack space
Unused space that is leftover when a File of X-1 size was given space of X
Bad Blocks/Clusters
Unusable sectors
Live forensics
Seeing what’s in live memory
Meterpreter
Power metasploit payload
Network forensics
study of data in motion.
Forensic software analysis
deconstruct malware and software. Use a VM to detonate Malware
EMbedded Device Forensics
IoT and Other Handheld devices
Electronic Discovery
Help lawyers with discovery process via Electronic Discovery tools
CSIRT
Computer Security Incident Response Team
800-61r2
NIST Incident Handling Guide
4 step lifecycle
800-61r2 lifecycle Step 1
Prep
800-61r2 lifecycle Step 2
Detection and Analysis
800-61r2 lifecycle Step 3
Containment, Eradication, and recovery
800-61r2 Step 4
Post-incident Activity