SECOPS 7: Identifying Malicious Activity Flashcards
1
Q
Deterministic Assessment Method
A
Known values to yield outcome for each proposed scenario
2
Q
Probabilistic Assessment Method
A
Consider a wide range of probable scenarios. Less accurate
3
Q
Syslog TAG field
A
Process that generated the message
4
Q
Syslog CONTENT field
A
Displays contents of the message
5
Q
ELSA search operators (2)
A
Boolean + Directives
6
Q
Fast flux
A
IP address mapping to DNS changes rapidly
7
Q
Double IP Flux
A
Name server and IP address changes rapidly
8
Q
DGA
A
Random domain names created rapidly. Often for C2