1/11
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
system hardening
making sure os are secure by staying up with updates , user accounts are secure, limimt network access, anti-virus
encryption
prevent access to application data files
efs , fde
encrypt network communication
endpoints
stop inbound and outboun attacks
endpoint detection and response (edr)
detect a threat through behavior analysis, machien learning, process monitorign and not just signatures
investigate the threat by a root cause analysis
repsond to threat by isolating the system, quarantine the htreat, rollback to a previous config
how is an edr automated
api
host based firewall
allows or disallows incoming or outgoing application traffic
also identify and block unkown processses
host based instrusion prevention systems (hips)
recognize and block known attacks
secure os and app configs, validate incoming service requests
often built into endpoint protection software
hips identification
signatures, heuristics, behavioral
buffer overflows, registry updates, writng files to the windows folder
access to non encrypted data
open ports and services should be closed
control access with a firewall
when do you unknowingly open ports
when installing os or apps
default password changegs
every network device has a amnagement interface so must change default settings to prevent atackers
removal of unnessscary software
all software contains bugs and remove all unused software as this will reduce your risk