SECOPS 9 Flashcards
1
Q
When did events occur?
A
In UTC
2
Q
Who?
A
IP/Domain associated with malware.
3
Q
Where did the infection come from?
A
Location of the attacker
4
Q
What type of malware is on the system?
A
Use sandbox to find out type of malware.
5
Q
Why? What does it do and what is it’s purpose?
A
Sandbox to see what it’s doing and find its intent.
6
Q
How did the malware get on the system?
A
Email, Scareware, etc.
7
Q
Threat investigation process (5)
A
Alert Detect Confirm Remediate Resolve
8
Q
X-Forwarded-For HTTP header
A
ID originating IP address, which often is a proxy.