Sec + 8 Flashcards
(26 cards)
What is MTTD, and which tool increases it drastically?
Mean time to detection. SOAR
What is an API and what does it do?
Application programming interface
Automates and streamlining of complex processes by linking together tools and systems.
Benefits of automation?
- Efficiency
- Enforcing baselines
- Standard infrastructure configurations
- Secure scaling
- Employee retention
- Reaction time
- Workforce multiplier.
Automation considerations.
- Complexity
- Cost
- Single point of failure
- Technical debt.
- Support
Incident response process
- Prep
- Detection
- Analysis
- Containment
- Eradication
- Recovery
- Lessons learned
What is CSIRT?
Cybersecurity incident response team
Stages of cyber kill chain
- Recon-calling employees, sending emails, dumpster diving, etc.
- Weaponization- create malware payload
- Delivery of payload.
- Exploitation- execution of code
- Installation - malware on asset
- Command and control
- Action on objectives- attack complete.
Diamond model.
- Adversary-hardest part to figure out
- Infrastructure - path to victim
- Capabilities
- Victim
What is intelligence fusion?
Orchestration of diverse cybersecurity data sources into a harmonious whole.
Stages of digital forensics
- Collection
- Examination-hashing
- Analysis
- Reporting
Order of evidence collection.
- Cpu cache
- Ram
- Swap/page file/virtual memory
- Hard drive
Automated reports benefits
- Real time insight
- Compliance tracking
- Effeciency
What is a business continuity plan(BCP)?
Road map to sustain procedures in face of distuptions.
What is the SDLC? List stages
Software development life cycle.
- Development.
- Test
- Staging
- Production
2 ways of software development.
- Waterfall-traditional. Linear
- Agile-short sprints that can be done in any order. Faster and more agile
Stages of risk management
- Risk identification-risk, threat, vulnerabilities
- Assessment-ad-hoc, recurring, one time, continuous
- Analysis-qualitative and quantitative
What is SLE?
Single loss expectancy
What is ARO
Annual rate of occurance.
What is ALEA and how is it calculated?
Annualized loss expectancy. Sle × apo
What is the exposure factor?
Measure of magnitude of loss
Represented by a %.
What is the risk register?
Detailed log of risks
What is KRI?
Key risk indicators
What does a risk owner do?
Manages specific risk
What is a neutral risk tolerance?
Balance of expansionary and conservative risk