Exam Review Flashcards
1
Q
What is the process for APT groups.
A
OSNT, External Takeover, Privilege Escalation, Lateral Movement+Internal Takeover, Hiding+info Theft
2
Q
1st Step for Network Forensic investigation
A
Check for malware signatures
3
Q
What method to test in Real Time
A
Dynamic Analysis
4
Q
Tool for Checking Network connections
A
Netstat
5
Q
Popup website to offer malware fix
A
Scareware
6
Q
Threat Hunting
A
Proactively looking for undetected Cyber threats hiding in a network.
7
Q
Threat Intelligence
A
Gathering threat info
8
Q
Logs
A
Store records of potentially important events
9
Q
Check site history
A
DNS Cache, ipconfig /displaydns
10
Q
Proof of data origin
A
Non-Repudiation
11
Q
monitor user during incidents
A
Accountability
12
Q
NIST IR
A
- Preparation and Planning
- Detection and Analysis
- Containment Eradication and Recovery
- Post-Incident Activity
13
Q
SANS IR = PICERL
A
- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Lessons Learned