Domain 7 (Security Operations) Flashcards

1
Q

Definition of an Event?

A

An observable change in state

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Definition of Alerts?

A

Flagged events that may require further investigation to determine if an incident has taken place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Definition of Incident?

A

Adverse impact to the system or network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the four steps of Incident Response?

A

Preparation (training, hiring);
Detection and Analysis;
Containment, eradication and recovery;
Post-Incident review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Definition of a Problem?

A

An incident with an unknown cause

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the five rules of Digital Evidence?

A
Must be:
Authentic
Accurate
Complete
Convincing
Admissible
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the seven steps of Forensic Investigation?

A
Identification
Preservation
Collection
Examination
Analysis
Presentation
Decision
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Locard’s principle of exchange?

A

When a crime is committed, the attackers takes something and leaves something behind

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What history must be recorded for the Chain of Custody?

A
How the evidence was:
Collected
Analyzed
Transported
Perserved
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the eight types of Evidence?

A
Direct evidence
Real evidence
Best evidence
Secondary evidence
Corroborative evidence
Circumstantial evidence
Hearsay evidence
Demonstrative evidence
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Direct Evidence?

A

Can prove a fact by itself and does not need backup information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Real Evidence?

A

Smoking gun. Object used in a crime.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Best Evidence?

A

Most reliable - signed contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Secondary Evidence?

A

Not strong enough to stand alone but can support another. IE Expert opinion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Corroborative Evidence?

A

Support evidence. Backs up other information presented.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Circumstantial Evidence?

A

Proves one fact which can be used to suggest another. Can’t stand on it’s own

17
Q

What is Hearsay Evidence?

A

Second hand oral or written. Can also be copies of a document.

18
Q

What is Demonstrative Evidence?

A

Presentation based like photos of crime scene

19
Q

What is Disk Shadowing?

A

Same as mirroring

20
Q

What is Electronic Vaulting?

A

Sends a BATCH of data to a remote location

21
Q

What is Remote Journaling?

A

Moves transaction logs that can be used to recreate database