Send a link to your students to track their progress
24 Terms
1
New cards
What is a Security Operations Center?
A team and function responsible for monitoring, detecting, investigating, and responding to cybersecurity threats.
2
New cards
What is a security event?
A recorded activity that may be normal, suspicious, or malicious.
3
New cards
What is a security alert?
A notification generated when activity matches detection logic or appears suspicious.
4
New cards
What is an investigation?
The process of gathering and analyzing evidence to determine what happened, whether it is malicious, and what action is required.
5
New cards
What is a security incident?
A confirmed or suspected event that threatens confidentiality, integrity, or availability and requires a coordinated response.
6
New cards
What is triage?
The initial review of an alert to determine validity, severity, scope, urgency, and required action.
7
New cards
What is a true positive?
An alert that correctly identifies malicious or unauthorized activity.
8
New cards
What is a false positive?
An alert that identifies legitimate activity as suspicious or malicious.
9
New cards
What is a false negative?
Malicious activity that occurs without being detected.
10
New cards
What is the difference between severity and priority?
Severity describes potential impact, while priority determines the order in which the issue should be handled based on severity, urgency, exposure, and business context.
11
New cards
What are the major incident-response phases?
Preparation, detection and analysis, containment, eradication, recovery, and lessons learned.
12
New cards
What is containment?
Limiting attacker access, preventing further damage, and stopping the spread of an incident.
13
New cards
What is eradication?
Removing malware, persistence mechanisms, unauthorized accounts, and the root cause of compromise.
14
New cards
What is recovery?
Safely restoring systems and operations while monitoring for recurrence.
15
New cards
What is root-cause analysis?
Determining how an incident occurred and what underlying weakness allowed it.
16
New cards
What is incident scope?
Every affected user, system, application, account, data source, and relevant time period.
17
New cards
When should an alert be escalated?
When activity may be malicious, involves privileged accounts or critical systems, requires containment, has unclear scope, or exceeds the analyst’s authority.