Prof Messer CompTIA Security+ SY0-701 - 4.8

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/20

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:50 AM on 5/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

21 Terms

1
New cards

NIST SP 800-61

incidence response lifecycle

- preparation

- detection

- containment, eradication and recovery

- post incident activity

2
New cards

preparing for an incident

Communication methods

- Phones and contact information

Incident handling hardware and software

- Laptops, removable media, forensic software,

digital cameras, etc.

Incident analysis resources

- Documentation, network diagrams, baselines, critical file hash values

Incident mitigation software

- Clean OS and application images

Policies needed for incident handling

- Everyone knows what to do

3
New cards

detecting security incidents

many diff detection sources

large amount of "volume"

- attacks come all the time, which ones are legit?

incidents are almost always complex

4
New cards

incident analysis

an incident might occur in the future

exploit announcement

- security patches

direct threats

attack is underway

- buffer overflow attempt

- antivirus identifies malware

- configuration changes

- network traffic anomalies

5
New cards

isolation and containment

dont let an attack run its course or spread

can be problematic sometimes

- malware can act differently in a sandbox

6
New cards

sandboxes

an isolated OS

you can run apps and see what happens

7
New cards

recovery after incident

remove bad, replace it with known good

remove malware

disable breached accs

fix vulnerabilities

recover the system

- restore from backups

- rebuild from scratch

- replace files

- tighten perimeter

8
New cards

lessons learned

learn and improve

post incident meeting

- better done ASAP

9
New cards

training for an incident

train team prior to incident

- initial response

- investigation plans

- incident reporting

etc

too late when an attack occurs

can be expensive

10
New cards

exercising (incident planning)

test yourself before an actual event

use well defined rules of engagement

- dont use production systems

limited time to run the tests

evaluate response

11
New cards

tabletop exercses

talking through a disaster drill on a table

- without performing a full scale drill

12
New cards

simulation

test with a simulated event

phishing sims

test internal security

13
New cards

root cause analysis

determine the ultimate cause of an incident

create a set of conclusions

can be more than 1 root cause

14
New cards

threat hunting

trying to find vulnerabilities before attackers

- game of cat and mouse

strategies constantly change

intelligence data is reactive

- cant see an attack until it happens

speed up reaction time

15
New cards

digital forensics

collect and protect info related to an intrusion

standard best practice process

- acquisition, analysis and reporting

16
New cards

legal hold

legal technique to preserve relevant info

separate repository for ESI (elec stored info)

ongoing preservation

17
New cards

chain of custody

keep integrity of evidence

use hashes and dig sigs to track who accesses data, and to keep integrity

label and catalog everything

- digitally tag all items

18
New cards

acquisition

obtain data

- disk, RAM, etc

some data may not be on a single system

- servers, network data, etc

for VMs, get a snapshot

- contains all files and info

look for any left behind digital items

- artifacts

- log info, recycle bins, browser bookmarks, etc

19
New cards

reporting (digital forensics)

document findings

overview of security event

detailed, step by step method of data acquisition process

analysis of findings

conclusion

20
New cards

preservation

isolate and protect it

work with copies

- keeps original data untouched and you have backups

live data collection is important

- data may be encrypted or harder to get after system is powered down

21
New cards

e-discovery

collect, prepare, review, interpret and produce elec documents

does not generally involve analysis

works together with digital forensics

- they do the analysis