Section 23.220 Alerting and Monitoring Activities Flashcards

Objective 4.4 Explain security alerting and monitoring concepts and tools

1
Q

Alerting and monitoring utilises a wide range of activities

Log Aggregation

A

Collects and consolidates log data from various sources into a central location

● Aids in troubleshooting, performance monitoring, security analysis, and compliance

● Provides a holistic view of system events for identifying issues and correlations

● Vital for maintaining system health and analyzing performance trends
Used for…
○ Detecting security incidents
○ Investigating breaches
○ Gathering evidence

Compliance - Auditors would need to review also

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Alerting and monitoring utilises a wide range of activities

Alerting

A

Involves setting up notifications for specific events or conditions

● Alerts can be triggered based on thresholds or anomalies

● Critical for proactive issue resolution, incident detection, and regulatory compliance

● Delivered through various channels, such as email, SMS, or push notifications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Alerting and monitoring utilises a wide range of activities

Scanning

A

Regularly examines systems, networks, or applications to identify vulnerabilities, misconfigurations, and issues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Scanning includes the following

Vulnerability scanning

A

Checks for vulnerabilities in systems, networks, or applications

■ Compares system’s state against a database of known vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Scanning includes the following

Configuration scanning

A

Checks for misconfigurations that could impact system
performance or security

■ Deviations are flagged for administrative review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Scanning includes the following

Code Scanning

A

Checks the source code of an application for potential
issues, such as security vulnerabilities or coding errors

● Utilises tools like Nessus, OpenVAS, and Qualys

● Helps maintain system health, security, and optimal performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Alerting and monitoring utilises a wide range of activities

Reporting

A

Generates summaries or detailed reports based on collected and analysed data

● Provides insights into system performance, security incidents, compliance status, and more

● Essential for compliance reporting and continuous improvement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Alerting and monitoring utilises a wide range of activities

Archiving

A

Involves long-term storage of data, including…

○ Log data
○ Performance data
○ Incident data

● Ensures data is retained for future reference, analysis, auditing, or compliance

● Important for legal and regulatory requirements

● Can be achieved using cloud storage solutions like Amazon S3 or Google Cloud Storage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Alerting and monitoring utilises a wide range of activities

Alert Response and Remediation/Validation

A

Managing and resolving identified issues based on alerts or scans

● Begin by taking appropriate actions such as…
○ Investigating
○ Escalating
○ Initiating

Initial response may include investigation, escalation, or predefined procedures

● Remediation: involves taking steps to address vulnerabilities or issues, such as patching or reconfiguration

● Validation: verifies that remediation efforts were successful in addressing the
identified problems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Quarantining

A

Isolates a system, network, or application suspected of being compromised

■ Prevents the spread of threats and limits potential impact

■ Commonly used when dealing with malware infections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Alert Tuning

A

Adjusts alert parameters to reduce errors, false positives, and improve alert relevance

■ Can involve changing alert thresholds, conditions, or delivery methods

■ Helps minimise excessive alerts and noise, making alerts more actionable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly