Module 5,6,7: SIEM and SOAR Flashcards

1
Q

SIEM

A

Security Information Event Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

NAC

A

Security Access Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SOC

A

Security Operations Center

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

NOC

A

Network Operations Center

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

SIEM Workflow

A
  1. Collection
  2. Parsing
  3. Evaluation
  4. Correlation
  5. Tickets managed by SOC
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SIEM Software

A
  1. QRadar (IBM)
  2. ArcSight
  3. AlienVault
  4. SPLUNK
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is SNORT

A

Network IDS/IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

WAF

A

Web Application Firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Log Types

A
  1. Application Logs

2. OS Logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Operators

A

AND, OR, NOT, IN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Aggregation Alerts

A

Similar attacks, Brute Force, port scanning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Correlation Alerts

A

Different Alerts, single target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Anomaly Alert

A

Suspicious Behavior

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SOAR

A

Security Orchestration Automation and Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Demisto

A

SOAR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Playbook

A

Flow of actions to respond to scenarios which may be automated or human response