Week 4 Flashcards

1
Q

What are two frameworks for playbooks?

A

-NIST
-IACD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is an important non-IT aspect to explain in a playbook?

A

The impact on wider operations outside of the IT department - helps to get both understanding and funds from management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is one way to reduce the amount of false positive alarms?

A

Buy proprietary tools, however these can hide the reason for the alarm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a problem with using ML for classification in a SOC?

A

It is good at seeing correlations but not so good at understanding causalities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does computer forensics deal with?

A

Digital evidence that is present in any top of crime - they do not necessarily work on cybercrimes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the foundation of digital forensics?

A

The practice of collecting, analysing and reporting on digital data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is important to remember regarding the state of the evidence during digital forensics?

A

It must not be changed in order to be valid in court

How well did you know this?
1
Not at all
2
3
4
5
Perfectly