7. Security Operations Flashcards
Define an event.
An observable change in state
Define an alert.
Flagged events that may require further investigation to determine if an incident has taken place
Define an incident.
Adverse impact to the system or network.
What are the 3 types of attacks?
- Dos/DDoS
- Malicious code
- Inappropriate usage
What are the four steps of incident control?
- Preparation
- Detection
- Containment
- Post-incident review
What is an incident with an unknown cause referred to as?
A problem
What are the defined steps of problem management?
- Incident notification
- Root cause analysis
- Solution determination
- Request for change
- Implement solution
- Monitor and report
What are the 7 steps of the forensic investigation process?
- Identification
- Preservation
- Collection
- Examination
- Analysis
- Presentation
- Decision
Define Direct evidence
Can prove a fact by itself and does not need back up information.
Define Real evidence
Physical evidence. The objects themselves that are used in a crime.
Define best evidence
Most reliable. i.e. a signed contract
Define secondary evidence
Not strong enough to stand alone, but can support other evidence. I.e. an expert opinion.
Define corroborative evidence
Support evidence, backs up other information presented. Cannot stand on its own.
Define circumstantial
Proves one fact which can be used to reasonably suggest another. Cannot stand on its own.
Who should conduct investigations?
Usually the FBI or Secret Service. You must be careful about 4th amendment rights.