7.1 Sec Ops Tech Flashcards

1
Q

change management

A
request
review
approve/reject
schedule and implement
document
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

patch management

A
evaluate
test
approve
deploy approved
verify
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

transitive/ non-transitive trust

A

transitive: trust relation between two domains and all of their subdomains

non-transitive: trust between domains, subdomains excluded

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

incident response

de re mi re re re le

A
  • detection
  • response (CIRT, investigation, evidence) -EINDÄMMUNG
  • mitigation (contain, limit the effect) EINDÄMMUNG
  • reporting (upper management, gov)
  • recovery (rebuild)
  • remediation (root cause analysis) SANIERUNG
    lessons learned
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

darknet

A

unused IPs monitored by IDS

few false positives because any traffic is illegitimate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

sampling

clipping

A

statistical

non-stat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

service burau

A

leases computer time in case of a disaster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

MAA

A

mutual assistance agreement, reciprocal agreement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

drp testing

A
  • read though: paperwork only
  • structured walk-trough: role play
  • simulation: role play with live testing
  • parallel
  • full interruption
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

types of incident

A

scanning (indicates that illegal activity may follow)
compromise
malicious code
dos

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

drp process

A

response
actoivate team
assess
reconstitution

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

developing drp

A
initiation
project scope
BIA
identify preventive controls
develop recovery strategies
develop contingency plan
implement, training, test
maintenance
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

RPO

Recovery point objective

A

maximum tolerable loss of data/work/availability an organization can withstand

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

RTO

recovery time objective

A

system recovery time, until it is running

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

MTD

A

RTO+WRT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

WRT

work recovery time

A

time needed to configure a recovered system

17
Q

MTBF

A

generated by vendor, hardware

18
Q

MOR

A

minimal operating requirements

19
Q

BCP

A

business/IT- focused

sustaining essential business processes while recovering

20
Q

DRP

A

IT-focused

recovery of capabilities at an alternate site

21
Q

COOP

A

not IT-focused

30 day uptime for STRATEGIC functions at alternate site

22
Q

OEP

Occupant Emergency Plan

A

minimizing loss of life, injury and damage

23
Q

forensic ediscovery

A

legal counsel gaining access to electronic information during civil legal proceedings. gather evidence

lots of electronic data is stored by organizations, so logistically and financially relevant

DATA RETENTION POLICY should claim to purge data when no longer needed to minimize impact of ediscovery

24
Q

RAID

A

3 byte level striping with dedicated parity
4 block level striping with dedicated parity
5 block level striping with distributed parity
6 block level striping with double distributed parity