Security assessments Flashcards

1
Q

What is a syslog?

A

A standard for message logging

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

What format does a central log collector inside a SIEM expect logs to be sent to it in?

A

Syslog format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is UEBA in regards to analyzing data?

A

User and Entity Behavior Analytics

An example of this would be a human capturing something that a SIEM or DLP system may have missed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is sentiment Analysis?

A

An example of using sentiment analysis would be paying attention (either programatically or normally) to what the general sentiment around your company looks like on social media. If they hate you they hack you more.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is SOAR?

A

Security orchestration, automation, and response.
When looking at SOAR vs. SIEM, both aggregate security data from various sources, but the locations and quantity of information being sourced are different. While SIEM will ingest various log and event data from traditional infrastructure component sources, a SOAR takes in all that and more.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly