Group 03: SOC and Incident Response

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/23

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:18 PM on 7/28/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

24 Terms

1
New cards
What is a Security Operations Center?
A team and function responsible for monitoring, detecting, investigating, and responding to cybersecurity threats.
2
New cards
What is a security event?
A recorded activity that may be normal, suspicious, or malicious.
3
New cards
What is a security alert?
A notification generated when activity matches detection logic or appears suspicious.
4
New cards
What is an investigation?
The process of gathering and analyzing evidence to determine what happened, whether it is malicious, and what action is required.
5
New cards
What is a security incident?
A confirmed or suspected event that threatens confidentiality, integrity, or availability and requires a coordinated response.
6
New cards
What is triage?
The initial review of an alert to determine validity, severity, scope, urgency, and required action.
7
New cards
What is a true positive?
An alert that correctly identifies malicious or unauthorized activity.
8
New cards
What is a false positive?
An alert that identifies legitimate activity as suspicious or malicious.
9
New cards
What is a false negative?
Malicious activity that occurs without being detected.
10
New cards
What is the difference between severity and priority?
Severity describes potential impact, while priority determines the order in which the issue should be handled based on severity, urgency, exposure, and business context.
11
New cards
What are the major incident-response phases?
Preparation, detection and analysis, containment, eradication, recovery, and lessons learned.
12
New cards
What is containment?
Limiting attacker access, preventing further damage, and stopping the spread of an incident.
13
New cards
What is eradication?
Removing malware, persistence mechanisms, unauthorized accounts, and the root cause of compromise.
14
New cards
What is recovery?
Safely restoring systems and operations while monitoring for recurrence.
15
New cards
What is root-cause analysis?
Determining how an incident occurred and what underlying weakness allowed it.
16
New cards
What is incident scope?
Every affected user, system, application, account, data source, and relevant time period.
17
New cards
When should an alert be escalated?
When activity may be malicious, involves privileged accounts or critical systems, requires containment, has unclear scope, or exceeds the analyst’s authority.
18
New cards
What should an investigation note contain?
Alert summary, affected entities, timeline, evidence reviewed, queries performed, findings, conclusion, actions taken, and recommended follow-up.
19
New cards
Why is evidence preservation important?
Evidence may be required to determine scope, support legal or compliance needs, validate conclusions, and conduct lessons learned.
20
New cards
What is chain of custody?
Documentation showing who collected, handled, transferred, stored, and examined evidence.
21
New cards
What is an incident playbook?
A documented response approach for a specific type of incident, such as phishing, malware, or account compromise.
22
New cards
What is the difference between containment and remediation?
Containment limits immediate damage, while remediation corrects the weakness or condition that allowed the incident.
23
New cards
Why should benign investigations still be documented?
Documentation supports auditing, future detection tuning, knowledge sharing, and consistent analyst decisions.
24
New cards
How should uncertainty be communicated?
Clearly separate confirmed facts, likely explanations, assumptions, and unresolved question