GCS 6-1: Response-Intro

0.0(0)
Studied by 1 person
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/75

flashcard set

Earn XP

Description and Tags

Google Cybersecurity Course 6 (Sound the Alarm: Detection and Response) Module 1 (Introduction to detection and incident response)

Last updated 2:35 AM on 8/30/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

76 Terms

1
New cards

bored

“Every day is something new, and I never get _____.”

2
New cards

life experience

“Cybersecurity is interesting because you can really bring your entire ____ ___________ to cybersecurity.”

3
New cards

Be assertive, have a plan, ask for help

Tips when looking for a mentor

4
New cards

Identify, Protect, Detect, Respond, Recover

Core functions of the NIST CSF

5
New cards

Preparation, Detection & Analysis, Containment Eradication & Recovery, Post-Incident Activity

NIST Incident Response Lifecycle

6
New cards

Incident

An occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

7
New cards

Event

An observable occurrence on a network, system, or device.

8
New cards

events

All security incidents are ______, but not all ______ are security incidents.

9
New cards

The 5 W’s of an incident

  • Who triggered the incident

  • What happened

  • When the incident took place

  • Where the incident took place

  • Why the incident occurred


10
New cards

Incident handler’s journal

A form of documentation used in incident response.

11
New cards

Preparation Planning/training process

Name the NIST lifecycle step

  • Set up uniform company email conventions

  • Create a collaborative, ethical environment where employees feel comfortable asking questions

  • Provide cybersecurity training on a quarterly basis


12
New cards

Detection and analysis

Name the NIST Lifecycle step

  • Identify signs of an incident

  • Filter external emails to flag messages containing attachments such as voicemails

  • Have an incident response plan to reference


13
New cards

Containment, eradication, and recovery

Name the NIST Lifecycle step

  • Communicate with sender to confirm the origin of the voice message

  • Provide employees with an easy way to report and contain suspicious messages


14
New cards

Post incident activity

Name the NIST Lifecycle step

  • Update the playbook to highlight additional red flags employees should be aware of.

  • Review processes and workflows related to permissions and adjust oversight of those permissions.


15
New cards

Computer security incident response teams

Aka CSIRT

16
New cards

CSIRT

A specialized group of security professionals that are trained in incident management and response.

17
New cards

Security analyst, Technical lead, Incident coordinator

Roles in CSIRT

18
New cards

Security analyst

A role in CSIRT. Their job is to investigate security alerts to determine if an incident has occurred. If an incident has been detected, the analyst will determine the criticality rating of the incident. Some incidents can be easily remediated by the security analyst and don’t require escalation.

19
New cards

Technical lead

A role in CSIRT. If an incident is highly critical, it gets escalated to the this role, who provide technical leadership by guiding security incidents through their lifecycle.

20
New cards

Incident coordinator

A role in CSIRT. During the incident lifecycle, this role tracks and manages the activities of CSIRT and other teams involved in the response effort. Their job is to ensure that incident response processes are followed and that teams are regularly updated on the incident status.

21
New cards

Incident Handling Team

Aka IHT.

22
New cards

SIRT, IHT

Other names for CSIRT.

23
New cards

Security Incident Response Team

Aka SIRT.

24
New cards

Ops Lead

Another name for Technical Lead

25
New cards

vulnerability

“Cybersecurity is very exciting. You never know when the next ____________ is going to be released.”

26
New cards

2021

When did the Log4j incident occur?

27
New cards

came together

“The entire company ____ ________ to investigate whether or not we were affected by this vulnerability.”

28
New cards

communicating

“The way to maintain clear and effective communication is by ___________ a lot.”

29
New cards

command, control, communication

For incident response to be effective and efficient, there must be clear ______, ______, and _______ of the situation to achieve the desired goal.

30
New cards

Command

Refers to having the appropriate leadership and direction to oversee the response.

31
New cards

Control

Refers to the ability to manage technical aspects during incident response, like coordinating resources and assigning tasks.

32
New cards

Communication

Refers to the ability to keep stakeholders informed.

33
New cards

Roles in CSIRTs

  1. Security analyst

  2. Technical lead

  3. Incident coordinator


34
New cards

Security operations center

Aka SOC.

35
New cards

SOC

An organizational unit dedicated to monitoring networks, systems, and devices for security threats or attacks. Structurally, this unit often exists as its own separate unit of within a CSIRT. It is involved in various types of blue team activities, such a network monitoring, analysis, and response to incidents.

36
New cards

Tier 1 SOC analyst

The first tier. It contains the least experienced analysts who are known as level 1s (L1s). They are responsible for

  • Monitoring, reviewing, and prioritizing alerts based on criticality or severity

  • Creating and closing alerts using ticketing systems

  • Escalating alert tickets to Tier 2 or Tier 3


37
New cards

Tier 2 SOC analyst

The second tier comprises of more experienced analysts, or level 2s (L2s). They are responsible for:

  • Receiving escalated tickets from L1 and conducting deeper investigations

  • Configuring and refining security tools

  • Reporting to the SOC Lead


38
New cards

Tier 3 SOC lead

The third tier is composed of the leads, or level 3s (L3s). These highly experienced professionals are responsible for:

  • Managing the operations of their team

  • Exploring methods of detection by performing advanced detection techniques, such as malware and forensics analysis

  • Reporting to the SOC manager


39
New cards

SOC manager

The person at the top of the pyramid and responsible for:

  • Hiring, training, and evaluating the SOC team members

  • Creating performance metrics and managing the performance of the SOC team

  • Developing reports related to incidents, compliance, and auditing

  • Communicating findings to stakeholders such as executive management


40
New cards

Forensic investigators

Commonly L2s or L3s who collect, preserve, and analyze digital evidence related to security incidents to determine what happened.

41
New cards

Threat hunters

Typically L3s who work to detect, analyze, and defend against new and advanced cybersecurity threats using threat intelligence.

42
New cards

Policies, standards, procedures

Elements of a security plan

43
New cards

Incident response plan

A document that outlines the procedures to take in each step of incident response.

44
New cards

Elements of an incident plan

  • Incident response procedures

  • System information

  • Other documents


45
New cards

Detection and management tools, documentation tools, investigative tools

Incident response tool types

46
New cards

Documentation

Any form of recorded content that is used for a specific purpose.

47
New cards

Playbooks, Incident handler’s journals, Policies, Plans, Final reports

Types of documentation

48
New cards

Playbook

A manual that provides details about any operational action.

49
New cards

Google Docs, OneNote, Evernote, Notepad++

Word processor tools

50
New cards

Jira

Ticketing system

51
New cards

Google Sheets, Audio recorders, Cameras, Handwritten notes

Other documentation tools

52
New cards

Intrusion detection system

Aka IDS

53
New cards

IDS

An application that monitors system and network activity and produces alerts on possible intrusions

54
New cards

Intrusion prevention system

Aka IPS

55
New cards

IPS

An application that monitors system activity for intrusions and take action to stop the activity

56
New cards

Snort, Zeek, Kismet, Sagan, Suricata

IDS and IPS tools

57
New cards

Endpoint detection and response

Aka EDR

58
New cards

EDR

An application that monitors an endpoint for malicious activity. These tools are installed on endpoints. They collect endpoint activity data and perform behavioral analysis to identify threat patterns happening on an endpoint. They also use automation to stop attacks without the manual intervention of security professionals.

59
New cards

Open EDR, Bitdefender Endpoint Detection and Response, FortiEDR

Examples of EDR tools

60
New cards

Endpoint

Any device connected on a network.

61
New cards

Detection categories

  • A true positive

  • A true negative

  • A false positive

  • A false negative


62
New cards

A true positive

An alert that correctly detects the presence of an attack

63
New cards

A true negative

A state where there is no detection of malicious activity. This is when no malicious activity exists and no alert is triggered.

64
New cards

A false positive

An alert that incorrectly detects the presence of a threat. This is when an IDS identifies an activity as malicious, but it isn’t. These are an inconvenience for security teams because they spend time and resources investigating an illegitimate alert.

65
New cards

A false negative

A state where the presence of a threat is not detected. This is when malicious activity happens but an IDS fails to detect it. False negatives are dangerous because security teams are left unaware of legitimate attacks that they can be vulnerable to.

66
New cards

Security Information and Event Management

Aka SIEM

67
New cards

SIEM

An application that collects and analyzes log data to monitor critical activities in an organization

68
New cards

SIEM

car components:dashboard, network endpoints:___________

69
New cards

SIEM process

  1. Collect and aggregate data

  2. Normalize data

  3. Analyze data


70
New cards

Security orchestration, automation, and response

Aka SOAR

71
New cards

SOAR

A collection of applications, tools, and workflows that uses automation to respond to security events.

72
New cards

Log analysis

The process of examining logs to identify events of interest.

73
New cards

Normalization

A process that converts data into a standard, structured format that is easily searchable.

74
New cards

Correlation

A part of the analysis process that involves the comparison of multiple log events to identify common patterns that indicate potential security threats.

75
New cards

Common SIEM tools

  • AlienVault OSSIM

  • Chronicle

  • Elastic

  • Exabeam

  • IBM QRadar Security Intelligence Platform

  • LogRhythm

  • Splunk


76
New cards

Aggregation

The process of gathering data from different sources and putting it in one centralized place.