SecOps 101 Flashcards

1
Q

What is Panther’s mission?

A

Go make security teams smarter and faster than attackers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does a security operations center (SOC) do?

A

Detect, analyze, and respond to cybersecurity threats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the two things SecOps is protecting?

A

Services and data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the four things that security’s operations do?

A
  1. Collect data from various sources
  2. Analyze data and find suspicious activity
  3. Alert the team to respond
  4. Investigate and determine if a breach had occurred
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does SIEM stand for?

A

Security
Information and
Event
Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Traditional SIEMS usually require _________ to deploy and maintain

A

High operational effort

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Traditional SIEMS have ______ and super slow queries to our data

A

Poor performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Traditional SIEMS often use ________ that restrict analysis capabilities

A

Proprietary languages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Traditional SIEMS usually involve______ that force teams to limit data collection

A

High licensing costs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What trait about Panther help SecOps team scale?

A

The fact that it’s fully cloud native - means that the architecture is designed for scale at a much lower cost

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What allows Panther to be more scalable at a lower cost?

A

The fact that it’s cloud native

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What allows Panther to analyze data much faster?

A

It’s built with with detection as code

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Panther’s product focus for FY 2024?

A

Being the best at detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the first step in Panther’s platform when data comes in?

A

It gets parsed and normalized

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What happens after data is ingested in Panther?

A

You can detect events based on rules and queries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What happens after the “detect” stage in Panther?

A

You then “investigate” aka analyze and report on activities

17
Q

What is Panther’s biggest differentiator?

A
  1. Ability to run at any scale on the ingestion and analysis side
  2. Detection as Code (DAS)