Sound the Alarm: Detection and Response: Module 1 Flashcards

(18 cards)

1
Q

Computer Security Incident Response Teams (CSIRT)

A

A group of security experts trained to handle and respond to cyber incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Documentation

A

Recorded information used for a specific task or purpose.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Endpoint Detection and Response (EDR)

A

A tool on devices like laptops or phones that watches for and stops suspicious behavior.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Event

A

Something that happens on a computer, network, or device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

False Negative

A

When something bad happens, but the system misses it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

False Positive

A

When the system thinks something bad happened, but it’s actually fine.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Incident

A

A real or likely threat to important information or systems, like a hack or rule violation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Incident Handler’s Journal

A

Notes taken during an incident to keep track of what happened.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Incident Response Plan

A

A step-by-step guide on what to do during a cyber incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Intrusion Detection System (IDS)

A

A tool that watches for bad activity and sends alerts but doesn’t stop it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Intrusion Prevention System (IPS)

A

A tool that watches for and also blocks bad activity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

National Institute of Standards and Technology (NIST) Incident Response Lifecycle

A

A 4-step plan for handling cyber incidents: Prepare, Detect, Respond, and Learn.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Playbook

A

A guide that tells you exactly how to handle certain tasks or incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Security Information and Event Management (SIEM)

A

A tool that collects and checks logs to find and alert on threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Security Operations Center (SOC)

A

A team that watches over a company’s networks and devices for cyber threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Security Orchestration, Automation, and Response (SOAR)

A

A system that uses automation to help security teams respond to incidents faster.

17
Q

True Negative

A

Nothing bad happened, and the system didn’t alert—just like it should.

18
Q

True Positive

A

A real threat was detected correctly by the system.