4.3 Incident Investigation Flashcards

1
Q

Vulnerability scans

A
  1. Uses database of known vulnerabilities to scan systems based on a signature
  2. Run on systems to ensure that they are properly configured and hardened
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security Information and Event Management (SIEM) (2)

A
  1. Consolidates logs from multiple systems for analysis
  2. Has logic to find correlations in the data to help identify potential breaches
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Define sensor relative to SIEM

A

Can provide network traffic data to SIEM in a standardized format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define SIEM alerts

A

Capability of SIEM to analyze data and provide alerts based on this

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Define syslog

A

A standard utility for transferring log files from a device to a central location, works across many different OS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Define slog & syslog-ng

A

Syslog-like implementations on Linux if it doesn’t have syslog

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Define journalctl

A

A tool that allows querying logs stored in a special binary format on Linux systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Define NXLog

A

A syslog alternative that runs as daemon on Linux

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Define NetFlow

A

A standard for gathering network statistics from switches, routers, and other devices into a central repository for analysis that is compatible with multiple manufacturers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Define IP flow information export (IPFIX)

A

Newer version of NetFlow with extended capabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Define sFlow

A

NetFlow and IPFIX can consume resources during collection so sFlow is alternative solution that just takes samples of network traffic to reduce resource usage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly