SECOPS 9 Flashcards

1
Q

When did events occur?

A

In UTC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who?

A

IP/Domain associated with malware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Where did the infection come from?

A

Location of the attacker

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What type of malware is on the system?

A

Use sandbox to find out type of malware.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why? What does it do and what is it’s purpose?

A

Sandbox to see what it’s doing and find its intent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How did the malware get on the system?

A

Email, Scareware, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Threat investigation process (5)

A
Alert
Detect
Confirm
Remediate
Resolve
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

X-Forwarded-For HTTP header

A

ID originating IP address, which often is a proxy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly