Module 4 Flashcards

1
Q

what are logs?

A

a record of events that occur within an organization’s systems

source of data that the tools are designed to organize

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what are SIEM tools? what does SIEM stand for?

A

Security Information and Event Management. An application that collects and analyzes log data to monitor critical activities in an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is splunk? what does SPLUNK Enterprise do?

A

a data analysis platform and SPLUNK Enterprise provides SIEM solutions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is SIEM Enterprise?

A

a self hosted tool used to retain, analyze, and search an organization’s log data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Chronicle?

A

a **cloud-native **SIEM tool that stores security data for search and analysis

From Google

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is cloud-native?

A

Chronicle allows for fast delivery of new features

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does security analysts use SIEM tools for?

A
  • analyze filtered events and patterns
  • perform incident analysis
  • proactively search for threats
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are playbooks?

A

a manual that provides details about any operation action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what is the official term for packet sniffer? what is it?

A

Network Protocol Analyzer. A tool designed to capture and analyze data traffic within a network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what is a dashboard?

A

tool used to visually communicate information or data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are common types of packet sniffers?

A
  • TCP Dump
  • Wireshark
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are two types of playbooks?

A
  • chain of custody
  • protecting and perserving evidence
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what is chain of custody?

A

the process of documenting evidence possession and control during an incident lifecycle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Protecting and Perserving Evidence Playbook?

A

the process of properly working with fragile and volatile digital evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly