SECOPS 12: SOC WMS and Automation Flashcards

1
Q

WMS

A

Tags/ID’s, tracks a security event, and tracks the actions to deal with the event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Tool to orchestrate & automate IR process

A

WMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

WMS aka

A

SOAR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

SOAR stands for

A

Security Orchestration Automation and Reporting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

System that performs containment and eradication

A

WMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Sequential workflow

A

Flow-chart style. One step to the next

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

State machine

A

Progress from state to state

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Rules-Driven

A

Rules dictate process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Guides analysts through the triage and response procedure

A

Workflow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

IR lifecycle (4)

A

Preparation
Detection and Analysis
Containment, Eradication, Recovery
Post incident activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Tier 1 Analyst

A

Monitors alerts, triages security alerts, Collects data to escalate to Tier 2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Tier 2 Analyst

A

Deep IA by correlating data. Determines affect. Advises on remediation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

IR Handler

A

Manages incident. Executes containment. Comms.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Forensics specialists

A

Gather, analyze data for investigation. Maintains data integrity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Reverse engineering specialist

A

ID’s TTP’s and IOC’s. Signature writing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

RESTful API

A

Used to send/receive data between tools

17
Q

Command line API’s

A

Often one off uses between WMS and other systems

18
Q

TAXII

A

Standardizes automated exchange of threat info.