LP - Automation, Orchestration, & Incident Response Flashcards
Orchestration involves managing several or many
automated tasks or processes
Automation invooles generating a single task to run automatically
without any human intervention
IdM stands for
Identity management
Security group firewalls are on layer
3/5 and are stateful packet filters
Benefits of Automation
- Efficiency and productivity
- Time Savings
- Enforcing baselines
- Standard infrastructure configuration
- Secure scalability
- Employee retention
- Reaction time
- Force multiplier
SPOF stands for
single point of failure
Incident Response Life Cycle
Preparation - detection - analysis and escalation - containment - eradication and recovery - lessons learned
IRT stands for
incident response team
MSSP stands for
managed security service providers
PUPs stand for
potentially unwanted programs
RCA stands for
root cause analysis
Root cause analysis (RCA) steps
- Define the problem
- Collect data
- Identify possible causal factors
- Identify the root cause(s)
- Recommend and implement solutions
Cyber Kill Chain is
A - advanced - Targeted, coordinated, purposeful
P- persistent - Targeted, coordinated, purposeful
T - threat - Person(s) with intent, opportunity and capability
7-step Cyber Kill Chain
- Recon
- Weaponization
- Delivery
- Exploitation
- Installation
- Command and control
- Exfiltration of data
E-discovery phases are:
- Identifying and collecting documents
- Sorting through data by relevance
- Creating production sets
- Data management
Order of Volatility
- CPU and its cache
- Kernel statistics, tables and caches
- Memory (RAM)
- Temporary file systems and swap/slack space
- Disk drives and volumes
- attached removable drives
- Logged data to a remote location
- Copies of data to archived media/cloud
SOAR (security orchestration, automation and response) can do one or more of these
- Threat and vulnerability management
- Incident response
- Security operations automation
Four types of SOAR automation
- Defensive
- Forensic
- Offensive
- Deception
Three types of SOAR action
- Enrichment
- Esclation
- Mitigation