SECOPS 7: Identifying Malicious Activity Flashcards

1
Q

Deterministic Assessment Method

A

Known values to yield outcome for each proposed scenario

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Probabilistic Assessment Method

A

Consider a wide range of probable scenarios. Less accurate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Syslog TAG field

A

Process that generated the message

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Syslog CONTENT field

A

Displays contents of the message

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

ELSA search operators (2)

A

Boolean + Directives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Fast flux

A

IP address mapping to DNS changes rapidly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Double IP Flux

A

Name server and IP address changes rapidly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

DGA

A

Random domain names created rapidly. Often for C2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly