Chapter 10 Flashcards

1
Q

Use 3 words to describe the chapter 10 incident detection and analysis

A

Indicators of compromise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Name a few list of indicators of compromise

A

Manipulation to files
DDOS
Something off to the network traffic
Unusual traffic behavior

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does indicators of compromise give the organization

A

Gives you workstation names, ip addresses, behavior-based information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Escalation of privileges, strange account behaviors, and bots are an example of which type of indicator of compromise?

A

Behavior-based

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are ossec and tripwire an example of?

A

Host intrusion detection systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Explain what a DNS amplification attack is

A

Service requesting on crack
too many queries that require large responses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How can you tell there is a DNS related IOC

A

Abnormal levels of DNS queries
Strange DNS names
Too many DNS fail requests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Describe fast-flux in a few words. Think of Jordans on release day

A

It’s when there are several IP addresses tied to one domain name. Those IP’s switch out fast.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

List terms associated with keeping or acquiring evidence of an incident. Think of UPL stuff

A

Chain of custody
Preservation
Legal hold
Data integrity validation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly