Casp test Flashcards
A natural disaster may disrupt operations at Site A, which would then cause an evacuation. Users are unable to log into the domain from their workstations after relocating to Site B.
Drag answer to Directory serveron site A
A natural disaster may disrupt operations at Site A, which would then cause the pump room at Site B to become inoperable.
Drag answer to SCADA
Master Controller
A natural disaster may disrupt operations at Site A, which would then cause unreliable Internet connectivity at Site B due to route flapping.
Modify BGP Config
Code snippet 1 or SQL query that includes ?
SQL injection - perform sanitization
if code has “get”
switch to “post”
AAA Server IP:
10.1.0.10
default eap TLS
F5o4l3l2y1!
VPN Concentrator
AES 256gcm128
F504l3l2y1!
10.1.2.1
WAPA
WAP*:A- Disable unneeded services
Laptop A
Laptop A- Disable unneeded services
Laptop B
Laptop B,. Enabled Disk encryption & Disable unneeded services
Switch A
Switch A- Change default administrative password & Disable mmeeded services
Switch B
Switch B- Disable unneeded services
PC-A
PC-B
PC-A - Disable·unneeded services
PC-B * Disable unneeded services
PC-C
- Patch management, Disable unneeded services
this will show you ip, port, pid, name of task.
$sudo netstat -nltp
this will show you ip, port, pid, name of task.
to see status
$sudo systemctl status -full name service-
to compare
to kill process
$sudo kill -9 -pid- Kills the PID
to stop process
$sudo systemctl stop
-full name service- Stops service
to disable process 5th command
$sudo systemctl disable -full name service-
Disables at startup
command to perform after process is diabled at startup to see network connections
$sudo netstat -nltp
command to double check the status
$sudo systemctl
status -full name service- double checking
10.1.45.65
SFTP Server Disable 8080
10.1.45.66
Email Server Disable 415 and 443
10.1.45.67
Web Server Disable 21, 80
10.1.45.68
UTM Appliance Disable 21
During the course of normal SOC operations, three anomalous events occurred and were flagged as potential IoCs. Evidence for each of these potential IoCs is provided.
IOC 1 - Update - nothing
IOC 2 - Footprinting - Block ping across
IOC 3 - P2p - block known bad ports