SECOPS 10: SOC Playbook (Not needed for the exam) Flashcards
Security analytics is accomplished by:
Collecting, correlating, and analyzing a wide range of data.
BGP Black-holing
Blocks IP addresses in seconds
IAM security device has an unexpected feature…
Device quarantine
Plays
self-contained, fully documented, prescriptive procedures for finding and responding to undesired activity
High Fidelity report
Guarantied true positive. Not a policy violation.
Investigative report
Might be an infection, policy violation, or normal activity.
Anything less than 100% certainty is investigative.
Can INV reports become HF?
Yes, with tuning over time.
Play objective statement
Describes what a play is looking for and why it’s worthwhile to run.
Query system
Basically a security system like a logging solution, SIEM, large data warehouse, etc.
Data query
Specific syntax used on a security system to identify reported activity
Play “action”
Actions to take during IR phase
Play “analysis”
Documentation and training material needed to understand the query
Play “reference”
Outside info like wiki or ticketing system