Domain 4 Flashcards
SELlinux
Security-Enhanced Linux (SELinux) is a robust security mechanism that operates at the core of many Linux distributions
Netflow
NetFlow (a technology initially developed by Cisco) has since evolved into the IP Flow Information Export (IPFIX) IETF standard, making it accessible beyond Cisco environments. NetFlow defines traffic flows based on shared characteristics, known as keys, and groups them into flow labels
SNMP
The SNMP is a widely used protocol used for network management. It operates with a key component known as the Management Information Base (MIB), which is essentially a database of network information
port 161
Data lose prevention
DLP is an outbound network tool whose role is to prevent PII and sensitive data from leaving the network by email or removable devices.
Agent based collection
uses software agents on individual devices or endpoints within a network.
agentless collection
as the name suggests, operates without the need for specialized agent deployment on endpoints.
SCAP
SCAP is a framework that enables compatible vulnerability scanners to assess whether a computer adheres to a predefined configuration baseline.
False negative
A false negative means that there is a vulnerability that has already been patched, but the scanner does not detect it.
Isolation duration
Isolation duration determines how long a system should remain in quarantine based on the severity of the alert and the steps taken for remediation.
SNMP agent
SNMP agents are software modules or processes running on network devices, such as routers, switches, servers, and even IoT devices.
SNMP Traps
SNMP traps are asynchronous notifications sent by SNMP agents to SNMP managers without a prior request
MITRE attack framework
MITRE is a US government-sponsored company whose aim is to help prevent cyberattacks.
Cyber Kill Chain
Originally developed by Lockheed Martin as a military model designed to identify the steps of an enemy attack, the Cyber Kill Chain (formerly Kill Chain) has since been adapted to build a framework to support cybersecurity teams’ awareness of potential cyberattacks. This framework allows them to trace each step of an attack, granting increasing clarity with the completion of each of the following stages:
Reconnaissance
Calling employees, sending emails, social engineering, dumpster diving
Soar
SOAR is an automated tool that integrates all of your security processes and tools in a central location
MITRE
MITRE is a US government-sponsored company whose aim is to help prevent cyberattacks.