Activity App Flashcards

1
Q

Known bad files

A

Detections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Behaviorally suspicious activity

A

Detections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Prevented actions

A

Detections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Blocklisted hashes

A

Detections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Manual detections

A

Detections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In progress

A

Detection status option

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True positive

A

Detections status option

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

False positive

A

Detections status option

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Ignored

A

Detections status option

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Steps to assign a detection

A
  1. Select checkbox
  2. Update & assign
  3. Select assign to and Set Status
  4. Update
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is included in an incident?

A
  1. Detections
  2. Associated processes
  3. Connections between detections and associated processes
  4. Tactics & Techniques involved
  5. Killed or blocked activities
  6. Hosts/users involved
  7. Whether the attack is active
  8. Timeline
  9. Incident status
How well did you know this?
1
Not at all
2
3
4
5
Perfectly