Sec + 8 Flashcards

(26 cards)

1
Q

What is MTTD, and which tool increases it drastically?

A

Mean time to detection. SOAR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is an API and what does it do?

A

Application programming interface

Automates and streamlining of complex processes by linking together tools and systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Benefits of automation?

A
  1. Efficiency
  2. Enforcing baselines
  3. Standard infrastructure configurations
  4. Secure scaling
  5. Employee retention
  6. Reaction time
  7. Workforce multiplier.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Automation considerations.

A
  1. Complexity
  2. Cost
  3. Single point of failure
  4. Technical debt.
  5. Support
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Incident response process

A
  1. Prep
  2. Detection
  3. Analysis
  4. Containment
  5. Eradication
  6. Recovery
  7. Lessons learned
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is CSIRT?

A

Cybersecurity incident response team

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Stages of cyber kill chain

A
  1. Recon-calling employees, sending emails, dumpster diving, etc.
  2. Weaponization- create malware payload
  3. Delivery of payload.
  4. Exploitation- execution of code
  5. Installation - malware on asset
  6. Command and control
  7. Action on objectives- attack complete.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Diamond model.

A
  1. Adversary-hardest part to figure out
  2. Infrastructure - path to victim
  3. Capabilities
  4. Victim
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is intelligence fusion?

A

Orchestration of diverse cybersecurity data sources into a harmonious whole.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Stages of digital forensics

A
  1. Collection
  2. Examination-hashing
  3. Analysis
  4. Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Order of evidence collection.

A
  1. Cpu cache
  2. Ram
  3. Swap/page file/virtual memory
  4. Hard drive
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Automated reports benefits

A
  1. Real time insight
  2. Compliance tracking
  3. Effeciency
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a business continuity plan(BCP)?

A

Road map to sustain procedures in face of distuptions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the SDLC? List stages

A

Software development life cycle.

  1. Development.
  2. Test
  3. Staging
  4. Production
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

2 ways of software development.

A
  1. Waterfall-traditional. Linear
  2. Agile-short sprints that can be done in any order. Faster and more agile
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Stages of risk management

A
  1. Risk identification-risk, threat, vulnerabilities
  2. Assessment-ad-hoc, recurring, one time, continuous
  3. Analysis-qualitative and quantitative
17
Q

What is SLE?

A

Single loss expectancy

18
Q

What is ARO

A

Annual rate of occurance.

19
Q

What is ALEA and how is it calculated?

A

Annualized loss expectancy. Sle × apo

20
Q

What is the exposure factor?

A

Measure of magnitude of loss
Represented by a %.

21
Q

What is the risk register?

A

Detailed log of risks

22
Q

What is KRI?

A

Key risk indicators

23
Q

What does a risk owner do?

A

Manages specific risk

24
Q

What is a neutral risk tolerance?

A

Balance of expansionary and conservative risk

25
What is risk exemption?
Exempting entity from risk due to impractical or unfeasable rules.
26
What is RPO?
Recovery point objective. Max age of files that can be lost without consequences.