7. Security Operations Flashcards
Define an event.
An observable change in state
Define an alert.
Flagged events that may require further investigation to determine if an incident has taken place
Define an incident.
Adverse impact to the system or network.
What are the 3 types of attacks?
- Dos/DDoS
- Malicious code
- Inappropriate usage
What are the four steps of incident control?
- Preparation
- Detection
- Containment
- Post-incident review
What is an incident with an unknown cause referred to as?
A problem
What are the defined steps of problem management?
- Incident notification
- Root cause analysis
- Solution determination
- Request for change
- Implement solution
- Monitor and report
What are the 7 steps of the forensic investigation process?
- Identification
- Preservation
- Collection
- Examination
- Analysis
- Presentation
- Decision
Define Direct evidence
Can prove a fact by itself and does not need back up information.
Define Real evidence
Physical evidence. The objects themselves that are used in a crime.
Define best evidence
Most reliable. i.e. a signed contract
Define secondary evidence
Not strong enough to stand alone, but can support other evidence. I.e. an expert opinion.
Define corroborative evidence
Support evidence, backs up other information presented. Cannot stand on its own.
Define circumstantial
Proves one fact which can be used to reasonably suggest another. Cannot stand on its own.
Who should conduct investigations?
Usually the FBI or Secret Service. You must be careful about 4th amendment rights.
What does RAID 0 mean?
Stripping across different drives
What does RAID 1 mean?
Mirroring one drive to another, for redundancy.
What does RAID 5 mean?
Stripping across hard drives with parity.
Define Server clustering
A group of servers that are managed as a single system. Not all clusters do load balancing.
What should you always check with performing an unscheduled backup?
Make sure it is a copy!
Define a Copy Backup
Same as a full back up, but Archive Bit is not reset.
Define a full backup
Back up EVERYTHING. Archival but is reset.
Define Incremental back up
Back up all files that have been modified since last back up. Archive bit is reset.
Define differential backup
Backs up all files that have been modified since last full back up. Archive but is not reset.
Define disk shadowing
A type of database backup. Mirroring technology that can update one or more copies of data at the same time.
Data saved to two different media types for redundancy.
Define electric vaulting
A type of database back up.
Copy of modified file is sent to a remote location where an original back up is stored.
Transfers bulk backup information.
Define remote journaling
A type of data base back up
Moves the journal or transaction log to a remote location, not the actual files.