(9) Detection And Analysis Flashcards

1
Q

According to NIST 800-61, Describe the importance of profiling network and systems

A

Profiling networks and systems is important to measure how extended activity looks on a system. It will improve how an org identifies normal activity during detection and analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

According to NIST 800-61, describe how Understanding normal behavior of users, systems, etc works

A

Understanding normal behavior of users, systems, networks and apps work is important (also called baselining) because it helps understand and identify when something is out of the ordinary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

According to NIST 800-61, describe the importance of creating a logging policy that specifies information that must be logged by systems, apps, etc.

A

A policy that specifies the information that must be logged by systems, apps, etc. is important and it should specify where those log records should be stored and how long the data should be retained

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

According to NIST 800-61, describe the point of performing event correlation

A

Performing event correlation to combine information is usually performed by Security Information Event Management (SIEM) system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

According to NIST 800-61, describe why clocks across servers, workstations, etc

A

Synchronizing clocks across servers, workstations, etc. is all about facilitating the correlation of log entries. Orgs get this by using a Network Time Protocol (NTP).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

According to NIST 800-61, what is the importance of maintaining a knowledge base of critical information

A

Maintaining a knowledge base that contains critical information about systems and apps is useful to responders of an incident. It should include information about profiles, usage patterns, and other information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

According to NIST 800-61, What is the importance of capturing network traffic once it is suspected?

A

Capturing network traffic once it is suspected is important, because it helps provide critical details of an attackers intentions and activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

According to NIST 800-61, why should information be filtered?

A

Information should be filtered because incident investigations involve a TON of information, and it is impossible to determine it all without both inclusion and exclusion filters. The incident response team could wish to create predefined filters to assist with future analysis efforts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

According to NIST 800-61, Why should assistance from external sources be included?

A

Assistance from other sources should could range from a google search to contacting an infosec company depending on the situation. The parameters should be clear.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly