Week 3 Flashcards

1
Q

What does SIEM stand for?

A

Security Information & Event Management

SIEM is a security platform that ingests event logs and offers a single view of this data with additional insights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the primary function of SIEM technology?

A

Supports threat detection and security incident response through real-time collection and historical analysis of security events

SIEM collects data from various sources and presents it as actionable information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What notable surge occurred in the environmental services industry in 2023?

A

61,839% increase in HTTP-based DDoS attacks

DDoS attacks accounted for half of all HTTP traffic in the industry.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a False Positive (FP) in the context of SIEM?

A

An incorrect identification of a threat or vulnerability by a system or tool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a True Positive (TP) in SIEM terms?

A

A correct identification of a threat or vulnerability by a system or tool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
  • Event and Log Collection
  • Normalization
  • Aggregation

What service provides these features?

A

Security Information and Event Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the CIA Triad?

A

A framework in information security that includes Confidentiality, Integrity, and Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the key aspects of confidentiality?

A

Data classification, access control, encryption, and authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Integrity in the context of the CIA Triad?

A

Assurance that data remains accurate, reliable, and unaltered during its lifecycle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does Availability mean in the CIA Triad?

A

Ensuring that data, systems, and resources are accessible and operational when needed by authorized users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Why is the CIA Triad important for organizations?

A

It helps organizations assess risks, make decisions about security measures, and establish security policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is an Open Source SIEM solution?

A

A cost-effective alternative to commercial SIEM products that is highly customizable

Examples include ELK Stack, OSSIM, and Graylog.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What service has these features?
* Correlation
* Real-time security monitoring and analysis
* Incident investigation and forensics
* Compliance

A

SIEM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Fill in the blank: The CIA Triad helps organizations strike the right balance between _______.

A

[competing requirements based on their specific needs and risk tolerance]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the purpose of data retention policies?

A

To ensure data is preserved for the appropriate duration and securely destroyed when no longer needed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the role of Load Balancing in Availability?

A

Distributes network traffic across multiple servers to prevent overloading any single server

17
Q

What is the significance of Service Level Agreements (SLAs) in Availability?

A

Establish SLAs with service providers to ensure that critical services meet predefined availability standards

18
Q

What should organizations assess when evaluating third-party vendors?

A

How well these vendors can maintain the confidentiality, integrity, and availability of data and services