4.9 Given a scenario, use data sources to support an investigation

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/18

flashcard set

Earn XP

Description and Tags

This set of flashcards covers important concepts related to data sources for incident response and digital forensics as discussed in the lecture.

Last updated 6:55 PM on 3/23/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

19 Terms

1
New cards

In the context of an incident response case, a _______ is something that can be subjected to analysis to discover indicators.

data source

2
New cards

Common data sources include log files from network appliances, system memory, and _______ generated by host computers.

media device file system data

3
New cards

The 'Vs' that describe issues with large amounts of data include volume, velocity, variety, ________, and value.

veracity

4
New cards

A security information and event management (SIEM) tool aggregates and correlates multiple _______ sources.

data

5
New cards

An event dashboard provides a console to support day-to-day incident response and gives a summary of information drawn from underlying _______ sources.

data

6
New cards

A SIEM can be used for alert reporting and ________ reports that communicate the level of threats and incidents.

status

7
New cards

Operating systems maintain logs to record _______ as users and software interact with the system.

events

8
New cards

Windows logs include Application, Security, and _______ logs.

System

9
New cards

Linux distributions can use syslog or _______ for logging events, depending on the system.

Journald

10
New cards

The source of logged events will typically include a host or network address, a process name, and categorization/______ fields.

priority

11
New cards

An application log file is managed by an _______ rather than the operating system.

application

12
New cards

An endpoint log monitors events from security software running on the host rather than the OS, and can include host-based firewalls and _______ detection.

intrusion

13
New cards

A vulnerability scanner can log each _______ detected to a SIEM.

vulnerability

14
New cards

Network logs are generated by appliances such as routers and _______.

firewalls

15
New cards

A firewall audit event will record a date/timestamp, the interface on which the rule was triggered, whether the rule matched incoming or _______ traffic.

outgoing

16
New cards

Analyzing packet contents can help reveal the tools used in an _______.

attack

17
New cards

Metadata can help establish timeline questions, such as when and where a _______ occurred.

breach

18
New cards

An email's Internet header includes address information for the recipient and sender, plus details of the servers handling _______ transmission.

message

19
New cards

The MTA routes the message to the recipient, with the message passing via one or more additional _______ servers.

SMTP

Explore top notes

note
Transport in Flowering Plants
Updated 855d ago
0.0(0)
note
WW2 1939-1945
Updated 1389d ago
0.0(0)
note
Metaphysics
Updated 1151d ago
0.0(0)
note
Going For Baroque
Updated 1367d ago
0.0(0)
note
Chapter 26: Sexual Jurisprudence
Updated 1080d ago
0.0(0)
note
2024Chem. IMFs ↓↑
Updated 584d ago
0.0(0)
note
Transport in Flowering Plants
Updated 855d ago
0.0(0)
note
WW2 1939-1945
Updated 1389d ago
0.0(0)
note
Metaphysics
Updated 1151d ago
0.0(0)
note
Going For Baroque
Updated 1367d ago
0.0(0)
note
Chapter 26: Sexual Jurisprudence
Updated 1080d ago
0.0(0)
note
2024Chem. IMFs ↓↑
Updated 584d ago
0.0(0)

Explore top flashcards

flashcards
Latin 1A Vocab List #4
27
Updated 677d ago
0.0(0)
flashcards
Week 15 - Outbreak Investigation
64
Updated 1197d ago
0.0(0)
flashcards
Science Study Guide
36
Updated 1152d ago
0.0(0)
flashcards
duits examenidioom 26,27
26
Updated 1107d ago
0.0(0)
flashcards
Sp4 Un1A (23-24) | El arte
30
Updated 944d ago
0.0(0)
flashcards
Spanish: Family Vocab
29
Updated 537d ago
0.0(0)
flashcards
Latin 1A Vocab List #4
27
Updated 677d ago
0.0(0)
flashcards
Week 15 - Outbreak Investigation
64
Updated 1197d ago
0.0(0)
flashcards
Science Study Guide
36
Updated 1152d ago
0.0(0)
flashcards
duits examenidioom 26,27
26
Updated 1107d ago
0.0(0)
flashcards
Sp4 Un1A (23-24) | El arte
30
Updated 944d ago
0.0(0)
flashcards
Spanish: Family Vocab
29
Updated 537d ago
0.0(0)