Incident Response and Recovery Flashcards
What is clock synchronization?
Prevents clock difference between client and server so that analysis of systems event logs are much easier
What is eradication?
Finding and eliminating all copies of casual agents such as malware files or unauthorized user
How you provide incident response support to forensics investigations?
Secure the scene, protect evidence, establish and maintain chain of custody of evidence
What are the phases of incident response?
- Detection
- Characterization
- Containment
- Eradication
- Restoration
- Reporting
Preparation precedes first detection
What kind of things might be an indicator of compromise?
Recognizable malware signatures, attempts to access IP addresses, or domain names associated with known or suspected botnet control server
What is the main difference between WIPS and WIPS as compared with NIPS and NIDS?
Wireless detection and prevention needs to extend further into Layer 1 and 2 traffic and may also involve RF surveillance and mapping to identify interference, jamming, or rogue devices.
Wired do not go into Layer 1 or 2