CySA Section 7 Operating System Security

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/66

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:14 PM on 9/30/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

67 Terms

1
New cards

The OS is both the ____ and the richest source of security telemetry available to an analyst

primary attack surface

2
New cards

The OS is both the primary attack surface and the richest source of ____ available to an analyst

security telemetry

3
New cards

The kernel is

the core of the OS

4
New cards

Rootkits operate at the

kernel level to hide processes, files, and network connections from user-space detection tools

5
New cards

Kernel space has unrestricted

hardware access

6
New cards

User space

where applications run with restricted privileges. This separation is a core security boundary

7
New cards

_____ and DEP (Data Execution Prevention) are OS memory protection mechanisms that make exploitation harder

ASLR (Address Space Layout Randomization)

8
New cards

ASLR (Address Space Layout Randomization) and _______ are OS memory protection mechanisms that make exploitation harder

DEP (Data Execution Prevention)

9
New cards

OS-level events feed

everything analysts use

10
New cards

Windows Event ID 4688

process creation

11
New cards

Windows Event ID 7045

New service installed

12
New cards

MITRE ATT&CK organizes adversary behavior by

tactic and technique against specific OS platforms

13
New cards

For questions about OS architecture and security operations, answers tied to

improved telemetry visibility or reduced attack surface are the correct direction

14
New cards

A user-space process ___________ is a strong indicator of rootkit or privilege escalation activity

loading kernel modules or calling undocumented system calls

15
New cards

Hardening

the systematic process of closing every unnecessary entry point on a system. It applies at initial build and must be maintained continuously against configuration drift

16
New cards

The four main hardening pillars

disabling unnecessary services, applying patches, managing accounts and privileges (principle of least privilege), and enforcing configuration baselines

17
New cards

CIS Benchmarks

provide community-vetted hardening guidance

18
New cards

CIS Benchmark Level 1

basic with minimal performance impact

19
New cards

CIS Benchmark Level 2

defense-in-depth and potentially more operationally impactful

20
New cards

DoD STIGs

government-produced hardening guidance widely used in enterprise security environments

21
New cards

cloud environments, AWS Config, Azure Policy, and AWS Security Hub serve

the same function as on-premises hardening and compliance tools

22
New cards

Hardening scenario questions often present a system configuration and ask what should be changed. ______ are your reference answers.

CIS Benchmarks and STIGs

23
New cards

C:\Windows\System32

contains critical OS binaries (svchost.exe, lsass.exe, cmd.exe). Legitimate OS processes must run from this path

24
New cards

Masquerading (MITRE ATT&CK T1036)

involves naming malware after legitimate system processes and running it from an unexpected path

25
New cards

C:\Users[User]\AppData\Roaming and AppData\Local

writable without administrator privileges, making them prime locations for malware persistence without triggering UAC

26
New cards

C:\Windows\Temp and user Temp directories

common malware staging and drop zones. Executables running from Temp are almost always suspicious

27
New cards

Registry Run and RunOnce keys under HKLM and HKCU

are the most common Windows persistence locations (MITRE ATT&CK T1547.001

28
New cards

Autoruns from Sysinternals

the fastest tool for reviewing Windows persistence locations across Run keys, startup folders, scheduled tasks, and services

29
New cards

In PBQ process list questions the suspicious process is always the one running from an

unexpected path such as AppData, Temp, or the user's Downloads folder.

30
New cards

When told a process name looks legitimate, check

the file path first. The wrong path is the indicator

31
New cards

Linux uses a single unified directory tree rooted at /

The Filesystem Hierarchy Standard (FHS) defines the structure

32
New cards

/etc

contains critical system configuration files

33
New cards

/etc/passwd

user accounts

34
New cards

/etc/shadow

password hashes, readable only by root

35
New cards

/etc/sudoers

sudo privilege assignments

36
New cards

/etc/crontab

scheduled tasks used for persistence

37
New cards

/var/log

the primary log source

38
New cards

/var/log/auth.log (Debian/Ubuntu) and /var/log/secure (RHEL/CentOS)

capture authentication events

39
New cards

/var/log/audit/audit.log

captures kernel-level audit events via auditd

40
New cards

/tmp

world-writable and a common malware staging area

41
New cards

/dev/shm

an in-memory filesystem that enables fileless execution leaving no disk artifact

42
New cards

/proc

a virtual filesystem exposing live process information

43
New cards

/proc/[PID]/exe

points to a process's executable even if the file has been deleted from disk

44
New cards

A recently modified /etc/sudoers file during a breach window is

a critical finding. This is the Linux equivalent of a Registry Run key modification

45
New cards

Fileless malware on Linux executes from

/dev/shm; If a scenario describes malware with no file system evidence, /dev/shm and memory-resident execution are the answer

46
New cards

Every attack eventually becomes

a process

47
New cards

Process trees reveal

arent-child relationships that expose attacker behavior

48
New cards

lsass.exe

handles Windows authentication and is the primary target for credential dumping (T1003). It runs from System32, runs as SYSTEM, and never spawns child processes. Any deviation is a critical alert

49
New cards

svchost.exe

hosts Windows services. It should always have services.exe as its parent and run from System32

50
New cards

An svchost.exe with

an explorer.exe parent or running from AppData is malicious

51
New cards

On Linux, ____ manages services (PID 1)

systemd

52
New cards

Attackers create malicious systemd service units in ____ designed to blend with legitimate service names

/etc/systemd/system/

53
New cards

LOLBins (Living Off The Land Binaries)

legitimate OS tools abused for malicious activity. Windows examples include PowerShell, certutil.exe, and mshta.exe. Linux examples include curl, wget, and nc

54
New cards

For LOLBin questions, signature-based detection is insufficient. The correct answer will always involve

behavior-based detection combining the process with its network or file activity

55
New cards

Process analysis PBQs test three signals

unexpected path, unexpected parent process, and unexpected user context

56
New cards

Hardening is what you do at

intiial build

57
New cards

Configuration best practices

what you do continuously afterward to prevent and detect configuration drift

58
New cards

Group Policy enforces ______ across active directory

security configurations

59
New cards

Attackers who gain domain admin can modify

GPOs to disable Defender, disable logging, or add malicious startup scripts

60
New cards

AppLocker enforces

execution control based on path, publisher, or hash (user-mode enforced)

61
New cards

Windows Defender Application Control (WDAC) is

kernel-enforced and more resistant to bypass

62
New cards

is App Locker or WDAC the stronger control

WDAC

63
New cards

Critical Windows audit policies include

Audit Process Creation (required for Event ID 4688), Audit Logon Events, Audit Policy Change, and Audit Privilege Use

Default audit settings are insufficient

64
New cards

Vulnerability patching prioritization should combine

CVSS (severity score) with EPSS (probability of exploitation in the wild). CVSS score alone is insufficient for prioritization

65
New cards

Continuous configuration assessment using ______ detects drift before attackers can exploit it

Nessus, AWS Config, Azure Policy, or GCP Security Command Center

66
New cards

A host that stops generating Event ID 4688 during an investigation window is

actively suspicious, not just a logging gap. ttackers disable audit logging as an anti-forensic technique

67
New cards