4.4 Incident, apply mitigation techniques or controls to secure an environment Flashcards

1
Q

Endpoint configuration: what are the different security controls for endpoints?

A
  • Application approved /deny lists
  • OS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Endpoint configuration: why some application are allowed /denied ?

A

Because some app can be dangerous and contain vulnerabilities, trojan horses, malware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Endpoint configuration: why OS are important for security endopoint ?

A

Decisons are made in the OS:
- App: allow app with this unique identifier
- OS can allow digitally signed apps from certain publisher (ex: anything signed by microsoft is trusted but not the rest)
- Path: allow application that are install in a specific folder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Security configuration: what can be configured to tighten security?

A
  • Firewall rules
  • MDM
  • DLP
  • Content filter/ URL filter
  • Updating or revoking certificates
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security configuration: what is isolation?

A

Administratively isolate a compromised device from everything else

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Security configuration: what can be isolated?

A
  • Network: remediation VLAN
  • Process: limit app execution, prevent malicious activity
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Security configuration: what is containment?

A

Run application in its own sandbox

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Security configuration: why containment help in security?

A

Limit interaction with host OS and other application. Therefor, malware would have no method of infection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Security configuration: what is SOAR?

A

Security Orchestration, Automation and Response helps coordinate, execute and automate tasks between various people and tools all within a single platform.

Ex: reset password, create website certificate, backup data app

How well did you know this?
1
Not at all
2
3
4
5
Perfectly