Security Operations 4.8 Flashcards

1
Q

Preparing for an incident

A

Communication methods. Phones and contact information.

Incident handling hardware and software

Incident analysis and resources.

Incident mitigation software. Clean OS and application images.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Incident Planning.

A

Testing, Limited amount of time. Evaluate response.

Table top exercises. Performing a full-scale disaster drill takes times and has an opportunity cost.

Everyone sitting around a table and working through discussing what would be done in a IR.

See where there might be room for improvement in a IR situation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Simulation

A

Phishing simulation. Creating a phishing email attack. Send to your user community.
Test the phishing get the filter.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Root cause analysis

A

Determine the ultimate cause of an incident, find the root cause.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Threat hunting

A

Finding the attacker before they find you.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Digital forensics

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly