Module 01. Endpoint Security Flashcards
What is Endpoint Security Solution
Suite of Tools to protect workstations and end point devices.
AV, DLP, NAC, HIDS/HIPS, Encryption, Email protection, Monitoring
What does AV scan?
Anit Virus:
Scans Strings, Hash signatures, Heuristic Detection
What does False Positive do?
Stops legitimate access.
What does False Negative do?
Allows illegitimate entry
What is ZERO DAY?
new flaw exploited before vendor can patch it.
Packing and Encryption
compressed to avoid detection
Code Mutation
slightly changed code to avoid detection
Stealth Techniques
alter behavior of OS to avoid detection
Disabling AV Updates
allows new viruses to avoid detection
Fileless Attack
does not install software
How does AV work?
Detect, remove, or quarantine
How does Internal Firewall work?
Blocks incoming/outgoing connections
How does HIDS/HIPS work
Detects, protects, alerts upon malicious activity
How does Sandbox work
restricted environment used to run suspicious programs
What is BOYD
Bring Your Own Device