Module 5,6,7: SIEM and SOAR Flashcards
1
Q
SIEM
A
Security Information Event Management
2
Q
NAC
A
Security Access Control
3
Q
SOC
A
Security Operations Center
4
Q
NOC
A
Network Operations Center
5
Q
SIEM Workflow
A
- Collection
- Parsing
- Evaluation
- Correlation
- Tickets managed by SOC
6
Q
SIEM Software
A
- QRadar (IBM)
- ArcSight
- AlienVault
- SPLUNK
7
Q
What is SNORT
A
Network IDS/IPS
8
Q
WAF
A
Web Application Firewall
9
Q
Log Types
A
- Application Logs
2. OS Logs
10
Q
Operators
A
AND, OR, NOT, IN
11
Q
Aggregation Alerts
A
Similar attacks, Brute Force, port scanning
12
Q
Correlation Alerts
A
Different Alerts, single target
13
Q
Anomaly Alert
A
Suspicious Behavior
14
Q
SOAR
A
Security Orchestration Automation and Response
15
Q
Demisto
A
SOAR