Phase 4 Flashcards
What are the default windows event logs?
System, security, application
Which default windows tool is used to view windows logs?
Event viewer
What is the default location for log files in Linux?
/var/log
In addition to event files (*evtx), in which formats can you save windows logs?
Xml(.xml), text(.txt), comma separated value (*.csv)
Which two products were combined to create a SIEM?
Security event manager, security information manager
What is the default port for communications with elasticsearch?
9200
What is the default port for communications with kibana?
5601
Which operational level do cyber professionals generally think at from three discussed in this lecture (introduction to strategy?
Tactical
Which component of the log stash pipeline is closest to the raw data?
Input
Filters
Elastic search
Output
Input
What level requires communication of a plan and organizational buy-in of the strategy?
Strategic
What is the default port utilized by log stash to communicate with elastic search ?
9200
At which level is the vision of the organization laid out?
Strategic
After installing filebeats on a server to pull the syslog files, what port needs to be configured for communications on the log stash server, by default?
5443
Strategy is: (5 things)
Built with consideration of the threat
Planned
Built upon experience
Holistic
The efficient use of resources
What does the filter component accomplish in the log stash pipeline?
Allows customization of the search criteria used by kibana when pulling data from elastic search
Does the national security strategy discuss tactics? ( true or false)
False
all elastic stack components must be installed on the same server, true or false?
False
Strategic leaders must balance and prioritize risk? True or false
True
Which elastic stack component creates data visualizations?
Kibana
What are the “must haves” for organizational strategy? 4 things
Vision
Practice
Include all sectors
Consider all levels
Using the layered security model which tool is used at every layer?
SIEM
Strategy is not : (3 choices)
Leadership
Benchmarking
Best practices
How many pillars does the us 2017 national security strategy have?
4
Who would find the national security strategy document useful?
Everyone