SECOPS 11: SOC Metrics Flashcards

1
Q

SIEM Functions

A
Collection
Normalization
Correlation
Dedupe
Reporting tools
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

TTD

A

Time to Detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

TTD Defined

A

Time between malicious event on endpoint and detection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Components of dwell time (3)

A

Event
Event Analysis (Triage)
Report time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Contain time (1)

A

Contain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Business Impact (2)

A

Contain

Remediate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

TTD aka

A

Dwell time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly