Security + Domain 4.0 - Day 1 SOC & SIEM

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/19

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

20 Terms

1
New cards

Alerting

system that sends warnings when something unusual happens

2
New cards

monitoring

Watching systems and networks to spot problems or attacks

3
New cards

System Monitoring

Keeping an eye on devices to check their health, performance, and security

4
New cards

Baseline

starting measurement of how a system performs or how secure it is, used to spot changes later.

5
New cards

Application Monitoring

Watching software apps to make sure they don’t have errors.

6
New cards

Infrastructure Monitoring

Keeping an eye on parts that support IT systems

7
New cards

log aggregation

Collecting logs in one spot to find problems.

8
New cards

scanning

Checking systems or networks to find weaknesses or problems.

9
New cards

reporting

Sharing what was found during a scan

10
New cards

archiving

Saving old data in long-term storage

11
New cards

Alert Response

Acting fast when a system detects a problem.

12
New cards

Remediation

Fixing the problem.

13
New cards

Validation

Checking to make sure the fix worked.

14
New cards

SIEM

tool that collects and analyzes security data to spot problems fast.

15
New cards

agent

program that gathers data or performs tasks on a device.

16
New cards

agentless

Collecting data or managing devices without installing extra software on them.

17
New cards

splunk

tool that collects and analyzes computer data to help find problems

18
New cards

elastic stack (elk)

tools that collect, organize, and display data to help find and fix problems.

19
New cards

arcsight

security tool that gathers and analyzes data to spot cyber threats quickly.

20
New cards

qradar

security tool that collects and checks data from networks to detect and stop attacks fast.