9 - 3: Incident Investigation Flashcards

1
Q

Syslog

A

An old, still-used format for creating various types of logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Syslog components

A

1) Header (timestamp, source) 2) Facility, a 24-bit message describing where in the system it originated 3) Severity (from 0 being emergency to 7 being a debug error) 4) Message itself

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

syslog-ng

A

Added security and delivery enhancements in 1998

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Rsyslog

A

Added even more enhancements in 2004

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Log tagging

A

Associating keywords or other identifiers to make finding logs easier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Two advantages of SIEMS

A

1) Centralized log repository 2) Apply AI to analyze and interpret logs for anomalous material

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SOAR platform

A

Security, Orchestration, Automation, Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Playbooks

A

Procedures tied to policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Runbooks

A

Automated SOAR activity when triggered by an event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

SOC reports

A

Service Organization Control: audits a service provider does of itself so their customers don’t have to audit them directly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

SOC 1 reports

A

Most basic report, provide customers with assurance during their own financial audits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SOC 2 reports

A

Include more sensitive data related to confidentiality, integrity, and availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SOC 3 reports

A

Contain SOC 2 sensitive information, but also designed for publication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SOC Type 1 reports

A

Describe controls and provide auditors’ opinion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SOC Type 2 reports

A

Include controls, auditors’ opinion, as well as testing results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SOC in the US

A

American Institute of CPAs publishes Statement on Standards for Attestation Engagements Number 18

17
Q

SOC internationally

A

International Accounting and Assurance Standards Board publishes