SECOPS 11: SOC Metrics Flashcards
1
Q
SIEM Functions
A
Collection Normalization Correlation Dedupe Reporting tools
2
Q
TTD
A
Time to Detection
3
Q
TTD Defined
A
Time between malicious event on endpoint and detection
4
Q
Components of dwell time (3)
A
Event
Event Analysis (Triage)
Report time
5
Q
Contain time (1)
A
Contain
6
Q
Business Impact (2)
A
Contain
Remediate
7
Q
TTD aka
A
Dwell time