Domain 7: Assessment Management Flashcards
Name the 4 types of IDS events
- True positive
- True negative
- False positive
- False negative
- Types of IDS event
- A Worm spreading on a trusted network; NIDS alerts
True positive
- Types of IDS event
- User surfs the web to an allowed site; NIDS is silent
True negative
- Types of IDS event
- User surfs the web to an allowed site; NIDS alerts
False positive
- Types of IDS event
- A worm is spreading on a trusted network; NIDS is silent
False negative
- Type of NIPS
- Malicious traffic is identified and then “shot down”
Active response NIPS
- Type of NIPS
- Acts as a Layer 3-7 firewall device traffic flows through
Inline NIPS
Class of solutions that are tasked specifically with trying to detect or prevent data from leaving the organization in a unauthorized manner
Data loss prevention (DLP)
Name 4 endpoint security controls
- Antivirus
- Application whitelisting
- Removable media controls
- Disk encryption
- Endpoint Security Control
- App used to determine in advance which binaries are considered safe to execute on a given system
Application whitelisting
- The process of capturing a snapshot of the current system security configuration
- Can use helpful during a potential security incident
Baselining
Used to help mitigate the risks associated with hard disk failures
Redundant array of Inexpensive disks (RAID)
Achieves full data redundancy by writing the same data to multiple hard disks
Mirroring
- Increases read and write performance by spreading - data across multiple hard disks
- Writes can be performed in parallel across multiple disks rather than serially on one disk
Striping
- Achieves data redundancy calculating data in two drives and storing the results on a third
- After failed drive is replaces the RAID controller rebuilds the lost data from the other two drives
Parity