SOC Concepts Flashcards
What are the four steps in the NIST SP 800 61r2 framework
Preparation; Detection & analysis; Containment, Eradication, Recovery; Post-incident Activity
What are the 3 types of NIDS?
Inline, Network Tap, Passive
What is the difference between NIDS and HIDS
NIDS is network security monitoring traffic in networks. HIDS is End Point Security host and monitors individual devices.
What are the 7 layers in the OSI Model
Application, Presentation, Session, Transport, Network, Data Link, Physical.
What is the Application layer?
End User Layer. in charge of providing an interface for the user to interact, communicate, and give commands to the computer.
What is the Presentation Layer?
Syntax layer. is the translator between the machine and the user. This layer is also responsible for encryption and decryption.
What is the Session Layer?
Synch and sent to port. The session layer is responsible for managing sessions between machines to enable communication between them.
What is the Transport Layer?
End-to-end connections. The transport layer is responsible for the transparent transfer of data between two computers.
What is the Network layer?
Packets. The network layer is responsible for redirecting the connection and transferring the data between two different networks by physical means, in search of the best path that allows this data to reach its destination in the shortest time possible.
What is the Data Link layer?
Frames. This layer is in charge of the addressing and physical transmission of the data, carrying out its encapsulation, and separating them into frames that will be easily directed by the physical transfer media.
What is the Physical layer?
Physical structure. responsible for the topology and the global connections from the computer to the network that allows the transmission and the physical operation of the system.
What protocol is on Port 20,21?
File Transfer Protocol (FTP)
What protocol is on Port 22?
Secure Shell (SSH)
What protocol is on Port 23?
Telnet
What protocol is on Port 25?
Simple Mail Transfer Protocol (SMTP)