SECOPS 10: SOC Playbook (Not needed for the exam) Flashcards

1
Q

Security analytics is accomplished by:

A

Collecting, correlating, and analyzing a wide range of data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

BGP Black-holing

A

Blocks IP addresses in seconds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

IAM security device has an unexpected feature…

A

Device quarantine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Plays

A

self-contained, fully documented, prescriptive procedures for finding and responding to undesired activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

High Fidelity report

A

Guarantied true positive. Not a policy violation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Investigative report

A

Might be an infection, policy violation, or normal activity.

Anything less than 100% certainty is investigative.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Can INV reports become HF?

A

Yes, with tuning over time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Play objective statement

A

Describes what a play is looking for and why it’s worthwhile to run.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Query system

A

Basically a security system like a logging solution, SIEM, large data warehouse, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Data query

A

Specific syntax used on a security system to identify reported activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Play “action”

A

Actions to take during IR phase

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Play “analysis”

A

Documentation and training material needed to understand the query

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Play “reference”

A

Outside info like wiki or ticketing system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly