Class 12: Incident Response, Digital Forensics, Log Analysis, Monitoring Infrastructure, Applications, DLP, and Benchmarks

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/157

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:32 PM on 6/24/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

158 Terms

1
New cards

Cybersecurity incident

A cybersecurity incident is a successful or attempted violation of an asset’s confidentiality, integrity, or availability.

Example: An attacker attempts to access protected company data without authorization.

Memory trick: Incident = CIA is threatened or harmed.

Trick question tip: Successful and attempted security violations can both count as incidents.

2
New cards

Incident response

Incident response is the organized process for detecting, analyzing, containing, eradicating, recovering from, and learning from cybersecurity incidents.

Example: A security team follows a documented process after malware is detected on a workstation.

Memory trick: IR means respond, recover, and improve.

Trick question tip: If the question asks what to do after a security event, think incident response lifecycle.

3
New cards

Incident response lifecycle order

The CompTIA incident response lifecycle follows preparation, detection, analysis, containment, eradication, recovery, and lessons learned.

Example: A team prepares tools, detects suspicious activity, analyzes it, contains spread, removes the cause, restores service, and documents improvements.

Memory trick: Prepare, detect, analyze, contain, eradicate, recover, learn.

Trick question tip: Security+ may ask what phase comes next, so memorize the order.

4
New cards

Preparation phase

Preparation makes teams and systems ready before an incident by creating policies, procedures, communication plans, tools, staffing, playbooks, and hardened systems.

Example: A company builds an IR plan, assigns responders, configures monitoring, and prepares secure communication channels.

Memory trick: Preparation happens before the bad thing.

Trick question tip: Policies, procedures, contact lists, tools, staffing, and response resources point to preparation.

5
New cards

Preparation and hardening

System hardening during preparation reduces the chance or impact of incidents before an attack occurs.

Example: IT disables unnecessary services and applies secure baseline settings before an incident happens.

Memory trick: Harden first, respond easier later.

Trick question tip: Preventive security work before an incident belongs to preparation.

6
New cards

Incident response resources

Incident response resources are the people, tools, procedures, documentation, and communication methods needed to handle incidents effectively.

Example: A response team maintains forensic tools, contact lists, escalation paths, and incident playbooks.

Memory trick: Resources are what the team needs when trouble starts.

Trick question tip: Preparing tools and resources before an incident is preparation.

7
New cards

Incident Response Plan (IRP)

An IRP is a formal document listing procedures, contacts, resources, communication paths, and response guidance for different incident categories.

Example: The IRP explains how to respond to malware, data breach, and account compromise incidents.

Memory trick: IRP = incident playbook.

Trick question tip: Procedures, contacts, resources, and incident categories point to the IRP.

8
New cards

Incident category procedures

Incident category procedures define different response steps based on the type of incident.

Example: The IRP has separate procedures for malware infection, unauthorized access, and data exposure.

Memory trick: Different incidents need different playbooks.

Trick question tip: Incident response should be tailored to incident category.

9
New cards

Communication plan

A communication plan defines how incidents are reported, who is notified, which channels are used, and how sensitive information is controlled.

Example: The plan lists trusted contacts, escalation paths, and approved communication methods.

Memory trick: Communication plan says who talks, how, and when.

Trick question tip: Reporting lines, notification rules, contact lists, and communication channels point to a communication plan.

10
New cards

Out-of-band communication

Out-of-band communication uses a separate trusted channel outside potentially compromised corporate systems.

Example: Responders use an approved external phone or messaging channel instead of corporate email during a suspected compromise.

Memory trick: Out-of-band means outside the risky path.

Trick question tip: If corporate email may be monitored by an attacker, use out-of-band communication.

11
New cards

Need-to-know communication

Need-to-know communication limits incident details to trusted parties who require the information to perform their roles.

Example: Incident details are shared only with approved responders, legal, management, and required stakeholders.

Memory trick: Share only with people who need it.

Trick question tip: Limiting incident details reduces leaks and avoids tipping off attackers.

12
New cards

Stakeholder management

Stakeholder management controls communication with affected parties, regulators, law enforcement, customers, employees, executives, and public-facing groups.

Example: Legal and PR approve a customer notification before it is released.

Memory trick: Tell the right people with the right message.

Trick question tip: Affected parties, regulators, press, customers, and reputation point to stakeholder management.

13
New cards

Incident reporting obligation

An incident reporting obligation is a legal, regulatory, contractual, or operational requirement to notify specific parties about an incident.

Example: A company determines whether regulators or affected customers must be notified after a breach.

Memory trick: Some incidents must be reported by rule.

Trick question tip: Regulators, law enforcement, customers, or affected parties indicate reporting obligations.

14
New cards

CIRT, CSIRT, and CERT

CIRT, CSIRT, and CERT are related names for teams responsible for managing and responding to computer security incidents.

Example: A CSIRT analyzes alerts, coordinates containment, and documents recovery after a malware outbreak.

Memory trick: Different names, same incident-response team idea.

Trick question tip: CERT may mean an incident response team, not only a certificate authority.

15
New cards

SOC versus CIRT

A SOC is a centralized monitoring and alert triage function, while a CIRT or CSIRT coordinates incident response actions after escalation.

Example: The SOC detects suspicious activity and the CIRT manages containment and recovery.

Memory trick: SOC watches; CIRT responds.

Trick question tip: Continuous monitoring points to SOC; handling confirmed incidents points to CIRT or CSIRT.

16
New cards

Incident response roles

IR roles may include senior executives, CIRT managers, analysts, technicians, legal, HR, PR, and outside incident response providers.

Example: An executive authorizes major action, analysts investigate, technicians isolate systems, legal handles reporting, and PR manages public messaging.

Memory trick: IR is technical and organizational.

Trick question tip: Major incidents often require cross-department coordination, not just IT work.

17
New cards

Senior executive decision-maker

A senior executive decision-maker authorizes major incident response actions that affect business operations, risk, or public messaging.

Example: An executive approves taking a critical production system offline for containment.

Memory trick: Serious incidents need authority.

Trick question tip: Actions with major business impact require management or executive authorization.

18
New cards

Legal role in incident response

Legal evaluates laws, regulations, liability, evidence handling, reporting obligations, and law enforcement coordination during an incident.

Example: Legal advises whether a breach must be reported to regulators.

Memory trick: Legal keeps the response lawful.

Trick question tip: Laws, regulators, liability, evidence, or law enforcement point to legal.

19
New cards

HR role in incident response

HR handles employee-related incident issues such as insider concerns, contracts, workplace conflict, training gaps, or employment actions.

Example: HR supports an investigation involving suspected employee misuse of company resources.

Memory trick: HR handles the people side.

Trick question tip: Employee misuse, insider behavior, contracts, or training gaps point to HR.

20
New cards

PR role in incident response

PR manages public messaging, negative press, social media reaction, reputation, and customer-facing communications after serious incidents.

Example: PR prepares an approved public statement after a data breach.

Memory trick: PR protects the public message.

Trick question tip: Press, social media, reputation, and customer trust point to PR.

21
New cards

Incident response provider

An incident response provider is an outside organization retained to support or perform incident response work.

Example: A company hires an external provider to assist with forensic investigation and containment.

Memory trick: IR provider = outside help.

Trick question tip: Outsourcing some response duties points to an incident response provider.

22
New cards

Detection phase

Detection discovers indicators of threat actor activity or signs that a cybersecurity incident may have occurred.

Example: A SIEM correlates firewall alerts, IDS alerts, and authentication logs to identify suspicious activity.

Memory trick: Detection finds the clues.

Trick question tip: Alerts, reports, indicators, suspicious activity, and event correlation point to detection.

23
New cards

Indicator of an incident

An indicator of an incident is evidence suggesting that a security incident may have occurred or may be in progress.

Example: An IDS alert shows traffic matching known malicious behavior.

Memory trick: Indicator = clue, not final proof.

Trick question tip: Indicators must be analyzed before confirming an incident.

24
New cards

Automated versus manual detection

Automated detection uses tools such as IDS, IPS, EDR, SIEM, or monitoring platforms, while manual detection occurs when humans report or find suspicious activity.

Example: A SIEM raises an alert, and a threat hunter later finds abnormal account behavior.

Memory trick: Tools alert; people notice and hunt.

Trick question tip: Threat hunting, employee reports, customer reports, and law enforcement reports can all trigger detection.

25
New cards

Threat hunting

Threat hunting is proactive manual searching for signs of compromise or malicious activity before or beyond automated alerts.

Example: A threat hunter reviews logs and finds abnormal account behavior.

Memory trick: Threat hunting looks before the alert screams.

Trick question tip: Proactive searching for threats points to threat hunting.

26
New cards

Event correlation

Event correlation compares related events from different sources to identify patterns that may indicate malicious activity.

Example: Multiple failed logins, a firewall alert, and unusual outbound traffic are reviewed together.

Memory trick: Correlation connects the dots.

Trick question tip: Combining logs, alerts, and system data to identify patterns points to correlation.

27
New cards

Network and system data sources

Network data sources show communications and traffic behavior, while system data sources show host-level events such as logs, errors, system state, and security events.

Example: Firewall logs show unusual outbound traffic, while server logs show repeated access failures.

Memory trick: Network shows who talked; system shows what the host did.

Trick question tip: Traffic, firewall, and IDS point to network data. Host logs, errors, and system state point to system data.

28
New cards

Analysis phase

Analysis determines whether an incident has occurred and evaluates indicators to understand severity, scope, category, and impact.

Example: Analysts review alerts, logs, and system behavior to decide whether suspicious activity is a real incident.

Memory trick: Analysis asks, “Is this real, and how bad is it?”

Trick question tip: Confirming an incident and assessing severity belong to analysis.

29
New cards

Incident triage

Incident triage prioritizes incidents by severity, urgency, impact, affected data, affected systems, and available evidence.

Example: A possible breach of sensitive records is prioritized over a low-risk policy alert.

Memory trick: Triage decides what needs help first.

Trick question tip: Severity assessment and prioritization during analysis point to triage.

30
New cards

True positive versus false positive

A true positive is an alert that correctly identifies real malicious or policy-violating activity, while a false positive is a harmless event incorrectly flagged as suspicious.

Example: An analyst validates one alert as real malware and dismisses another as approved scanner traffic.

Memory trick: True means real; false means noise.

Trick question tip: Analysis separates confirmed incidents from alerts that should be dismissed.

31
New cards

Escalation

Escalation sends an incident to a higher-level responder, manager, specialist, or external provider when severity, complexity, or authority requirements exceed the first responder’s role.

Example: A severe data breach is escalated to senior incident responders and legal.

Memory trick: Escalation raises the case to the right level.

Trick question tip: Complex, severe, high-impact, or legally sensitive incidents often require escalation.

32
New cards

Scope and impact analysis

Scope identifies what systems, users, data, and services are affected, while impact measures the business, security, legal, or operational damage.

Example: A single infected database server with sensitive records may be higher priority than many low-value infected workstations.

Memory trick: Scope is how wide; impact is how bad.

Trick question tip: Count affected systems, but also consider sensitive data and business criticality.

33
New cards

Incident category and profile

Incident category identifies the type of incident, while an incident profile summarizes traits such as affected assets, attacker behavior, impact, and response needs.

Example: A ransomware profile includes encrypted systems, affected data, containment steps, and recovery requirements.

Memory trick: Category names it; profile describes it.

Trick question tip: Different incident categories require different playbooks.

34
New cards

Cyber kill chain mapping

Cyber kill chain mapping places observed attacker activity into stages such as reconnaissance, delivery, exploitation, installation, command and control, and actions on objectives.

Example: Analysts map phishing delivery, malware installation, and outbound command traffic to attack stages.

Memory trick: Kill chain shows where the attack is in the process.

Trick question tip: Mapping attacker activity to stages helps analysis and containment planning.

35
New cards

Playbook

A playbook gives step-by-step response guidance for a specific alert or incident scenario.

Example: A malware playbook tells analysts how to validate, contain, eradicate, recover, and document the incident.

Memory trick: Playbook = response recipe.

Trick question tip: Step-by-step guidance for a specific incident type points to a playbook.

36
New cards

Containment phase

Containment limits the scope and impact of a confirmed incident while responders prevent further damage.

Example: A compromised host is isolated from the production network while analysts continue investigating.

Memory trick: Containment keeps the incident from spreading.

Trick question tip: Isolation, blocking, restricting accounts, or limiting damage points to containment.

37
New cards

Containment decision

Containment decisions choose the best response based on incident type, severity, business impact, evidence needs, and available countermeasures.

Example: Responders decide whether to disconnect a host immediately or quietly monitor it first.

Memory trick: Containment is not one-size-fits-all.

Trick question tip: No single containment method fits every scenario.

38
New cards

Loss control

Loss control during containment evaluates what damage or theft has already occurred and how much more could happen if action is delayed.

Example: A team isolates a host before more confidential data can be exfiltrated.

Memory trick: Stop the bleeding.

Trick question tip: Preventing additional damage while preserving business operations is a containment clue.

39
New cards

Isolation and quarantine

Isolation removes or restricts a system, account, address, or file from normal activity, while quarantine places it in a controlled state for containment or remediation.

Example: A compromised endpoint is isolated from the network and a malicious file is quarantined.

Memory trick: Isolation separates; quarantine locks up.

Trick question tip: Host, file, address, or account quarantine points to containment or remediation.

40
New cards

Account containment

Account containment restricts, disables, resets, or monitors accounts suspected of compromise.

Example: A compromised account is disabled and its sessions are revoked.

Memory trick: Lock the account before it spreads damage.

Trick question tip: Credential compromise, suspicious logins, or account misuse point to account containment.

41
New cards

Eradication phase

Eradication removes the cause of the incident and restores affected systems to a secure state.

Example: After containment, the team removes malware, closes the exploited weakness, and applies patches.

Memory trick: Eradication removes the root problem.

Trick question tip: Removing malware, patching, and fixing insecure settings point to eradication.

42
New cards

Recovery phase

Recovery reintegrates cleaned and secured systems back into business operations.

Example: A restored server is returned to production after malware is removed and security checks pass.

Memory trick: Recovery brings the system back safely.

Trick question tip: Returning systems to operation after eradication points to recovery.

43
New cards

Backup restoration during recovery

Backup restoration during recovery restores systems or data from known-good backups after the incident cause has been removed.

Example: A server’s data is restored from backup after ransomware is eradicated.

Memory trick: Recover with clean backups.

Trick question tip: Restoring data before removing the cause can reintroduce the incident.

44
New cards

Security testing during recovery

Security testing during recovery validates that restored systems are secure before or after returning them to service.

Example: The team tests a recovered application to confirm the vulnerability is no longer present.

Memory trick: Test before trusting recovery.

Trick question tip: Verification before reintegration belongs to recovery.

45
New cards

Post-recovery monitoring

Post-recovery monitoring watches restored systems closely to detect recurrence or missed attacker activity.

Example: A recovered server is monitored for unusual traffic for several days after being returned to production.

Memory trick: Recovery is not done until you watch for relapse.

Trick question tip: Monitoring after restoration helps detect recurrence.

46
New cards

Lessons learned phase

Lessons learned analyzes the incident and response to identify improvements to procedures, controls, training, communication, and systems.

Example: After an incident, the team reviews what worked, what failed, and what should change.

Memory trick: Lessons learned turns pain into preparation.

Trick question tip: Post-incident review, improvement recommendations, and after-action reports point to lessons learned.

47
New cards

After-action report

An after-action report or lessons learned report summarizes what happened, what was affected, how the team responded, what worked, what failed, and what should improve.

Example: A report identifies that missing MFA allowed account compromise and recommends stronger authentication.

Memory trick: After-action report = incident debrief.

Trick question tip: Root cause and improvement recommendations belong in lessons learned.

48
New cards

Root cause analysis

Root cause analysis identifies the deeper reason an incident happened rather than only the immediate symptom.

Example: A stolen password caused account misuse, but the root cause was lack of MFA and weak user training.

Memory trick: Ask why until you find the real weakness.

Trick question tip: Root cause is deeper than the first visible problem.

49
New cards

Incident response iteration

Incident response may repeat through analysis, containment, eradication, and recovery until the incident is fully resolved.

Example: Responders restore one system, discover another affected system, and repeat containment and eradication.

Memory trick: IR can loop until clean.

Trick question tip: The lifecycle is structured but not always one-and-done.

50
New cards

Incident response versus disaster recovery

Incident response focuses on cybersecurity incidents, while disaster recovery focuses on restoring operations after major disruptions.

Example: Malware containment is incident response; restoring company-wide operations after a major outage is disaster recovery.

Memory trick: IR fights the security incident; DR restores the business.

Trick question tip: A cyber incident can trigger disaster recovery if it becomes a major operational disruption.

51
New cards

Digital forensics

Digital forensics collects, preserves, validates, analyzes, and reports digital evidence so investigators can understand what happened and support response or legal action.

Example: A forensic team images a drive and analyzes the copy to determine how a system was compromised.

Memory trick: Forensics preserves and explains evidence.

Trick question tip: Evidence collection, preservation, validation, and legal use point to digital forensics.

52
New cards

Due process

Due process means evidence must be collected, preserved, analyzed, and handled according to fair legal procedures and established rules.

Example: Investigators follow approved steps so evidence is not challenged in court.

Memory trick: Proper process protects the case.

Trick question tip: Improper evidence handling can make evidence inadmissible.

53
New cards

Legal hold

A legal hold requires preservation of information that may be relevant to a lawsuit, criminal investigation, regulatory matter, or similar proceeding.

Example: Normal deletion policies are suspended for emails, logs, backups, and records related to an investigation.

Memory trick: Legal hold means do not delete.

Trick question tip: Retention and deletion policies may need to be paused when legal hold applies.

54
New cards

Forensic acquisition

Forensic acquisition obtains evidence while preserving integrity, usually by creating a sound copy rather than analyzing the original device directly.

Example: Investigators create a bit-for-bit image of a hard drive and analyze a copy.

Memory trick: Acquire the evidence without changing it.

Trick question tip: Do not investigate the original media when a forensic image can be used.

55
New cards

Legal authority before acquisition

Legal authority must be confirmed before collecting evidence, especially when personal devices, BYOD, privacy, or employee rights are involved.

Example: A company verifies whether it can seize and image an employee’s personal laptop used for work.

Memory trick: Permission first, collection second.

Trick question tip: Improper collection can create legal problems and make evidence unusable.

56
New cards

Order of volatility

Order of volatility means collecting evidence from the most temporary sources first and least temporary sources later.

Example: A responder captures RAM and network connection data before imaging a powered-off drive.

Memory trick: Collect what disappears first.

Trick question tip: Volatile evidence can be lost when power is removed.

57
New cards

Volatile data

Volatile data is temporary information that may disappear when a system is powered off or changes state.

Example: RAM contains running processes, active network connections, open files, user sessions, and possible decrypted data.

Memory trick: Volatile data vanishes fast.

Trick question tip: RAM, cache, processes, network connections, and live sessions are volatile evidence.

58
New cards

Memory acquisition

Memory acquisition captures the contents of RAM for forensic or incident response analysis.

Example: A responder captures memory from a suspected compromised system before shutting it down.

Memory trick: Memory can hold live clues.

Trick question tip: Capture RAM early because it may contain active processes, network connections, keys, and decrypted data.

59
New cards

Disk imaging

Disk imaging creates a bit-for-bit copy of storage media, including active files, deleted files, free space, hidden data, and metadata.

Example: A forensic image captures the entire drive instead of copying only visible files.

Memory trick: Image the whole drive, not just files.

Trick question tip: A forensic image should capture deleted and hidden data, not only active files.

60
New cards

Write blocker

A write blocker prevents data from being written to the original evidence media during acquisition or analysis.

Example: A drive is attached to a forensic workstation through a write blocker before imaging.

Memory trick: Write blocker stops changes.

Trick question tip: Preventing accidental modification of source evidence points to a write blocker.

61
New cards

Hashing in forensics

Hashing creates a digital fingerprint used to verify evidence integrity before and after acquisition.

Example: Investigators hash the source drive, image the drive, and compare the image hash to the original hash.

Memory trick: Matching hashes mean matching evidence.

Trick question tip: Hash values prove whether evidence or an image changed.

62
New cards

Reference image versus analysis copy

A reference image is the validated preserved forensic image, while an analysis copy is a duplicate used for investigation.

Example: Analysts work from a copy while the reference image remains protected.

Memory trick: Preserve the master, analyze the copy.

Trick question tip: Forensic analysis should be performed on a copy, not the original evidence or preserved reference image.

63
New cards

Proof of integrity

Proof of integrity shows that evidence has not been modified since acquisition.

Example: Matching hashes prove the forensic image is unchanged from the source media.

Memory trick: Integrity proof means evidence stayed the same.

Trick question tip: Hashes and validation provide proof of integrity.

64
New cards

Chain of custody

Chain of custody is documentation showing who collected, handled, transferred, stored, and analyzed evidence, including when, where, methods, and tools used.

Example: A form records each person who handled a seized drive and when it changed hands.

Memory trick: Chain of custody tracks every handoff.

Trick question tip: Where, when, who collected, who handled, where stored, and tools used point to chain of custody.

65
New cards

Evidence labeling, bagging, and sealing

Evidence labeling identifies items, bagging protects and separates them, and sealing makes unauthorized access easier to detect.

Example: A seized drive is labeled, placed in a tamper-evident bag, sealed, and logged.

Memory trick: Label it, bag it, seal it.

Trick question tip: These steps support chain of custody and tamper detection.

66
New cards

Tamper-evident and antistatic evidence handling

Tamper-evident packaging shows signs of interference, while antistatic shielding protects electronic evidence from electrostatic discharge.

Example: A seized USB drive is sealed in a tamper-evident antistatic evidence bag.

Memory trick: Tamper-evident shows opening; antistatic prevents static shock.

Trick question tip: Electronic media should be protected from tampering and ESD.

67
New cards

Faraday bag

A Faraday bag blocks wireless signals to prevent remote communication with a seized device.

Example: A seized phone is placed in a signal-blocking bag to prevent remote wipe.

Memory trick: Faraday bag blocks signals.

Trick question tip: Remote wipe risk with mobile evidence points to Faraday-style shielding.

68
New cards

Secure evidence storage

Secure evidence storage protects evidence with access control, environmental controls, and documentation.

Example: Evidence is kept in a restricted room with controlled temperature, humidity, and fire protection.

Memory trick: Evidence must survive storage.

Trick question tip: Secure evidence facilities require more than a locked door; they also protect against damage and unauthorized access.

69
New cards

Forensic reporting

Forensic reporting documents how evidence was collected, methods used, findings, supporting evidence, conclusions, and limitations.

Example: A report explains how investigators reached conclusions based on logs, images, and validated evidence.

Memory trick: Report facts, not guesses.

Trick question tip: Forensic reports should be evidence-based, repeatable, and free of unsupported personal opinions.

70
New cards

Electronically stored information (ESI)

Electronically stored information is digital information that may be relevant to investigation or legal discovery, including active files, deleted files, metadata, logs, email, and unallocated space.

Example: Investigators search active files, deleted files, metadata, and storage artifacts during discovery.

Memory trick: ESI = digital records that may matter.

Trick question tip: Legal discovery and preservation often involve ESI.

71
New cards

Log data

Log data records activity from users, operating systems, applications, devices, and network controls.

Example: A login failure log records the account, time, host, and result.

Memory trick: Logs are the incident trail.

Trick question tip: Logs are often the most important source for detection, analysis, and timeline building.

72
New cards

Event metadata

Event metadata is data about a logged event, such as timestamp, host, username, process ID, severity, source, destination, and action.

Example: A log entry shows when a failed login occurred, which account was used, and which host generated the event.

Memory trick: Metadata tells when, where, who, and how serious.

Trick question tip: Timestamp, hostname, process ID, user, and severity are metadata clues.

73
New cards

Syslog

Syslog is a common logging format and transport method used by network devices and Unix-like systems to send event messages to a central collector.

Example: A router sends syslog messages to a SIEM.

Memory trick: Syslog ships event messages.

Trick question tip: Network devices, Linux systems, and centralized log collection often point to syslog.

74
New cards

Windows Event Viewer

Windows Event Viewer displays Windows logs such as security, system, application, setup, and forwarded events.

Example: An analyst reviews Windows security logs for failed logins and privilege changes.

Memory trick: Event Viewer shows Windows event records.

Trick question tip: Windows security event investigation points to Event Viewer or Windows event logs.

75
New cards

Linux syslog and journald

Linux systems often store logs through syslog files and journald, which stores logs in a binary journal viewed with journalctl.

Example: An analyst checks system logs and journal entries during a Linux investigation.

Memory trick: Syslog files and journald both tell Linux stories.

Trick question tip: journalctl and binary journal logs point to journald.

76
New cards

Application logs

Application logs record events generated by software applications and services, such as authentication failures, errors, transactions, and user actions.

Example: A business application logs repeated failed sign-in attempts.

Memory trick: Application logs show what apps did.

Trick question tip: Correlate application logs with host and network logs to understand an incident.

77
New cards

Firewall logs

Firewall logs record traffic decisions such as allowed, blocked, dropped, or rejected connections, along with source, destination, ports, protocol, and rule information.

Example: A firewall log confirms whether suspicious outbound traffic from a host was allowed or denied.

Memory trick: Firewall logs show who talked to whom and whether it got through.

Trick question tip: Use firewall logs to validate suspicious host network activity.

78
New cards

IDS versus IPS logs

IDS logs record suspicious traffic detections, while IPS logs may also record prevention actions such as blocks, resets, redirects, or shuns.

Example: An IDS logs a rule match, while an IPS logs that it reset a malicious connection.

Memory trick: IDS logs detection; IPS logs prevention.

Trick question tip: Prevention actions such as shun, reset, or redirect point to IPS logs.

79
New cards

Packet capture

Packet capture records network packets so analysts can inspect communication details, payloads when visible, and traffic behavior.

Example: An analyst pivots from an IDS alert to the packets that triggered it.

Memory trick: Packet capture shows the traffic itself.

Trick question tip: Pivoting from an alert to underlying packets supports deeper investigation.

80
New cards

SIEM

A SIEM collects, correlates, analyzes, reports, and displays security event and log data from many sources.

Example: A SIEM correlates a malware alert, router syslog event, and suspicious login into one incident.

Memory trick: SIEM gathers security events in one place.

Trick question tip: Centralized log correlation, dashboards, alerting, and reporting point to SIEM.

81
New cards

SIEM data inputs

SIEM data inputs include logs, alerts, event records, packet captures, flow data, malware alerts, appliance logs, host logs, and application logs.

Example: An IDS sensor, firewall, endpoint, and business application all send events to the SIEM.

Memory trick: Inputs feed the SIEM.

Trick question tip: SIEM usefulness depends on collecting relevant data from many sources.

82
New cards

SIEM reporting and dashboards

SIEM reporting summarizes security data for analysts, managers, auditors, or compliance needs, while dashboards visually display alerts, events, metrics, and status.

Example: A dashboard shows open alerts, event severity, affected hosts, and alert trends.

Memory trick: Reports summarize; dashboards show live status.

Trick question tip: Visual security summaries from many sources often come from SIEM dashboards.

83
New cards

SIEM alerting

SIEM alerting notifies analysts when correlated events or patterns indicate possible threats.

Example: The SIEM alerts when suspicious login activity is followed by unusual outbound traffic.

Memory trick: SIEM alerting rings the security bell.

Trick question tip: Alerting from correlated security data points to SIEM.

84
New cards

SIEM correlation rules

SIEM correlation rules define event patterns that trigger log-only events, alerts, alarms, or automated workflows.

Example: A rule raises an alarm when failed logins, impossible travel, and privileged access occur together.

Memory trick: Correlation rules decide when events matter together.

Trick question tip: Correlation combines multiple weak signals into a stronger detection.

85
New cards

Correlation rule criticality

Correlation rule criticality is the severity assigned when a SIEM rule matches event conditions.

Example: A SIEM classifies one rule match as log only, another as alert, and another as alarm.

Memory trick: Criticality tells how loud the SIEM should be.

Trick question tip: Log only, alert, and alarm are different response levels.

86
New cards

Alert tuning

Alert tuning adjusts SIEM alert behavior to reduce false positives while still detecting real threats.

Example: A team modifies a noisy login-failure rule so it alerts only when several related conditions occur.

Memory trick: Tuning makes alerts useful, not noisy.

Trick question tip: Reducing false positives without creating false negatives is the core challenge.

87
New cards

Alert fatigue

Alert fatigue happens when excessive low-value alerts overwhelm analysts and make real high-impact alerts easier to miss.

Example: Analysts become used to dismissing harmless alerts and overlook a serious intrusion.

Memory trick: Too many false alarms hide the real alarm.

Trick question tip: Noisy alerts and ignored dashboards point to alert fatigue.

88
New cards

SOAR

SOAR stands for Security Orchestration, Automation, and Response and helps automate or coordinate response workflows across tools and teams.

Example: A SOAR playbook gathers related logs and offers a one-click quarantine action.

Memory trick: SIEM sees; SOAR acts.

Trick question tip: Automation, orchestration, playbooks, and response workflows point to SOAR.

89
New cards

One-click quarantine

One-click quarantine is an integrated remediation action that lets an analyst isolate a host, address, or file through connected tools.

Example: An analyst clicks a SIEM action that uses endpoint integration to isolate a workstation.

Memory trick: One click starts containment.

Trick question tip: Quarantine through firewall or endpoint integration points to SOAR-style remediation.

90
New cards

Pivoting between sources

Pivoting between sources means moving from one event, alert, or indicator to related data sources for deeper investigation.

Example: An analyst pivots from an IDS alert to packets, firewall logs, and host logs.

Memory trick: Pivot means jump to supporting evidence.

Trick question tip: Inspecting related data behind an alert points to source pivoting.

91
New cards

Log retention and archiving

Log retention defines how long logs are kept, while archiving moves older logs to storage outside live analysis systems for compliance, investigation, or cost reasons.

Example: A SIEM keeps recent events searchable and moves older logs to archive storage.

Memory trick: Retain what policy requires; archive what live systems should not carry.

Trick question tip: Retention supports legal and compliance needs, while archiving protects SIEM performance.

92
New cards

Log rotation

Log rotation moves older log data out of active storage and into archive storage based on age, size, or policy.

Example: Logs older than a defined period are moved from live SIEM analysis to archive storage.

Memory trick: Rotation moves old logs aside.

Trick question tip: Moving outdated information to archive storage points to log rotation.

93
New cards

Retrospective investigation

Retrospective investigation uses stored historical logs or archived security data to investigate activity discovered after it occurred.

Example: Archived network traffic records help support a later forensic investigation.

Memory trick: Old logs can explain old attacks.

Trick question tip: Historical lookup after a new indicator is discovered points to retrospective investigation.

94
New cards

Alerting and monitoring defense in depth

Alerting and monitoring combine SIEM correlation, threat intelligence, analyst queries, alert validation, quarantine actions, playbooks, SOAR automation, pivoting, reporting, metrics, retention, archiving, and log rotation.

Example: A SIEM validates an alert, lets the analyst pivot to supporting data, triggers quarantine, reports trends, and archives evidence.

Memory trick: Correlate, validate, act, report, archive.

Trick question tip: SIEM monitoring is broader than alerts; it also supports automation, reporting, compliance, and investigation.

95
New cards
Monitoring infrastructure
Monitoring infrastructure uses reports, network monitors, flow collectors, alerts, and health checks to verify that network resources remain secure and available.<br><br><b>Example:</b> A manager reviews monitoring data to confirm switches, routers, firewalls, and access points are operating normally.<br><br><b>Memory trick:</b> Infrastructure monitoring watches the network’s body.<br><br><b>Trick question tip:</b> Infrastructure monitoring focuses on device health, availability, and traffic patterns, not only security alerts.<br><br>
96
New cards
Managerial and custom reports
Managerial reports summarize monitoring information for review, while custom reports answer specific monitoring or infrastructure questions.<br><br><b>Example:</b> A custom report shows firewall health, link utilization, and unusual traffic trends.<br><br><b>Memory trick:</b> Reports turn raw monitoring into reviewable evidence.<br><br><b>Trick question tip:</b> Not all issues appear as alerts, so reports help verify coverage and find trends.<br><br>
97
New cards
Network monitor versus traffic monitoring
A network monitor collects health and status data from infrastructure appliances, while traffic monitoring examines traffic moving across the network.<br><br><b>Example:</b> Monitoring a router’s CPU and temperature is network monitoring; analyzing sessions through the router is traffic monitoring.<br><br><b>Memory trick:</b> Device health versus traffic behavior.<br><br><b>Trick question tip:</b> CPU, memory, fan speed, and temperature point to network monitor; packet or flow behavior points to traffic monitoring.<br><br>
98
New cards
Infrastructure appliances
Infrastructure appliances are network devices such as switches, routers, access points, firewalls, and similar systems that support connectivity and security.<br><br><b>Example:</b> A monitoring platform checks access point availability and switch link errors.<br><br><b>Memory trick:</b> Appliances are the hardware pieces that keep the network running.<br><br><b>Trick question tip:</b> Switches, routers, firewalls, and access points are common monitored appliances.<br><br>
99
New cards
Device load monitoring
Device load monitoring tracks resource use such as CPU, memory, disk, connection state tables, and capacity on infrastructure appliances.<br><br><b>Example:</b> A firewall alert triggers when CPU utilization stays above an approved threshold.<br><br><b>Memory trick:</b> Load monitoring checks whether the device is overworked.<br><br><b>Trick question tip:</b> CPU, memory, disk, and state table values are device health metrics.<br><br>
100
New cards
State table monitoring
State table monitoring tracks the active connection records maintained by devices such as stateful firewalls.<br><br><b>Example:</b> A firewall state table grows rapidly during a traffic spike and is monitored for capacity issues.<br><br><b>Memory trick:</b> State tables track active sessions.<br><br><b>Trick question tip:</b> Firewalls commonly use state tables to track sessions, so state table exhaustion can affect availability.<br><br>