Chapter 10 Flashcards
Use 3 words to describe the chapter 10 incident detection and analysis
Indicators of compromise
Name a few list of indicators of compromise
Manipulation to files
DDOS
Something off to the network traffic
Unusual traffic behavior
What does indicators of compromise give the organization
Gives you workstation names, ip addresses, behavior-based information
Escalation of privileges, strange account behaviors, and bots are an example of which type of indicator of compromise?
Behavior-based
What are ossec and tripwire an example of?
Host intrusion detection systems
Explain what a DNS amplification attack is
Service requesting on crack
too many queries that require large responses
How can you tell there is a DNS related IOC
Abnormal levels of DNS queries
Strange DNS names
Too many DNS fail requests
Describe fast-flux in a few words. Think of Jordans on release day
It’s when there are several IP addresses tied to one domain name. Those IP’s switch out fast.
List terms associated with keeping or acquiring evidence of an incident. Think of UPL stuff
Chain of custody
Preservation
Legal hold
Data integrity validation