Introduction to detection and incident response Flashcards

1
Q

Computer security incident response teams (CSIRT):

A

A specialized group of security professionals that are trained in incident management and response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Documentation:

A

Any form of recorded content that is used for a specific purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Endpoint detection and response (EDR):

A

An application that monitors an endpoint for malicious activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Event:

A

An observable occurrence on a network, system, or device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

False negative:

A

A state where the presence of a threat is not detected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

False positive:

A

An alert that incorrectly detects the presence of a threat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Incident:

A

An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Incident handler’s journal:

A

A form of documentation used in incident response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Incident response plan:

A

A document that outlines the procedures to take in each step of incident response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Intrusion detection system (IDS)

A

An application that monitors system activity and alerts on possible intrusions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Intrusion prevention system (IPS):

A

An application that monitors system activity for intrusive activity and takes action to stop the activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Playbook:

A

A manual that provides details about any operational action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

National Institute of Standards and Technology (NIST) Incident Response Lifecycle:

A

A framework for incident response consisting of four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-incident activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Security information and event management (SIEM):

A

An application that collects and analyzes log data to monitor critical activities in an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Security operations center (SOC):

A

An organizational unit dedicated to monitoring networks, systems, and devices for security threats or attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Security orchestration, automation, and response (SOAR):

A

A collection of applications, tools, and workflows that uses automation to respond to security events

17
Q

True negative:

A

A state where there is no detection of malicious activity

18
Q

True positive

A

An alert that correctly detects the presence of an attack