Section 31 Incident Response and Forensics Flashcards
A set of procedures that an investigator follows when examining a computer security incident.
Incident Response
Program consisting of the monitoring and detection of security events on a computer network and the execution of proper responses to those security events.
Incident Management Program
Process of recognizing whether an event that occurs should be classified as an incident.
Identification
Focused on data restoration, system repair, and re-enabling any servers or networks taken offline during the incident response.
Recovery
Signals that are sent between two parties or two devices that are sent via a path or method different from that of the primary communications between the two parties or devices.
Out of band communication
Executives and managers who are responsible for business operations and functional areas.
Senior Leadership
Governmental organizations that oversee the compliance with specific regulations and laws.
Regulatory Bodies
The business or organization’s legal counsel is responsible for mitigating risk from civil lawmakers.
Legal
Used to ensure no breaches of employment law or employee contracts is made using an incident response.
Human Resources (HR)
Used to manage negative publicity from a serious incident.
Public Relations (PR)
Three variations of syslog which all permit the logging of data from different types of systems in a central repository.
Syslog/ry-slog/syslog-ng
A Linux command line utility used for querying and displayed logs from journald, the systemd logging service on linux.
Journalctl
A multi platform log management tool that helps to easily identify security risks, policy branches or analyze operational problems in server logs, operation system logs, and application logs.
Nxlog
A network protocol system created by CISCO that collects active IP network traffic as it flows in or out of an interface, including its point of origin, destination, volume and paths on the network.
Netflow
Short “sampled flow”, it provides a means for exporting truncated packets, together with interface counters for the purpose of network monitoring.
sflow