Exam Review Flashcards

1
Q

What is the process for APT groups.

A

OSNT, External Takeover, Privilege Escalation, Lateral Movement+Internal Takeover, Hiding+info Theft

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

1st Step for Network Forensic investigation

A

Check for malware signatures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What method to test in Real Time

A

Dynamic Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Tool for Checking Network connections

A

Netstat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Popup website to offer malware fix

A

Scareware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Threat Hunting

A

Proactively looking for undetected Cyber threats hiding in a network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Threat Intelligence

A

Gathering threat info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Logs

A

Store records of potentially important events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Check site history

A

DNS Cache, ipconfig /displaydns

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Proof of data origin

A

Non-Repudiation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

monitor user during incidents

A

Accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

NIST IR

A
  1. Preparation and Planning
  2. Detection and Analysis
  3. Containment Eradication and Recovery
  4. Post-Incident Activity
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SANS IR = PICERL

A
  1. Preparation
  2. Identification
  3. Containment
  4. Eradication
  5. Recovery
  6. Lessons Learned
How well did you know this?
1
Not at all
2
3
4
5
Perfectly