1/66
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
The OS is both the ____ and the richest source of security telemetry available to an analyst
primary attack surface
The OS is both the primary attack surface and the richest source of ____ available to an analyst
security telemetry
The kernel is
the core of the OS
Rootkits operate at the
kernel level to hide processes, files, and network connections from user-space detection tools
Kernel space has unrestricted
hardware access
User space
where applications run with restricted privileges. This separation is a core security boundary
_____ and DEP (Data Execution Prevention) are OS memory protection mechanisms that make exploitation harder
ASLR (Address Space Layout Randomization)
ASLR (Address Space Layout Randomization) and _______ are OS memory protection mechanisms that make exploitation harder
DEP (Data Execution Prevention)
OS-level events feed
everything analysts use
Windows Event ID 4688
process creation
Windows Event ID 7045
New service installed
MITRE ATT&CK organizes adversary behavior by
tactic and technique against specific OS platforms
For questions about OS architecture and security operations, answers tied to
improved telemetry visibility or reduced attack surface are the correct direction
A user-space process ___________ is a strong indicator of rootkit or privilege escalation activity
loading kernel modules or calling undocumented system calls
Hardening
the systematic process of closing every unnecessary entry point on a system. It applies at initial build and must be maintained continuously against configuration drift
The four main hardening pillars
disabling unnecessary services, applying patches, managing accounts and privileges (principle of least privilege), and enforcing configuration baselines
CIS Benchmarks
provide community-vetted hardening guidance
CIS Benchmark Level 1
basic with minimal performance impact
CIS Benchmark Level 2
defense-in-depth and potentially more operationally impactful
DoD STIGs
government-produced hardening guidance widely used in enterprise security environments
cloud environments, AWS Config, Azure Policy, and AWS Security Hub serve
the same function as on-premises hardening and compliance tools
Hardening scenario questions often present a system configuration and ask what should be changed. ______ are your reference answers.
CIS Benchmarks and STIGs
C:\Windows\System32
contains critical OS binaries (svchost.exe, lsass.exe, cmd.exe). Legitimate OS processes must run from this path
Masquerading (MITRE ATT&CK T1036)
involves naming malware after legitimate system processes and running it from an unexpected path
C:\Users[User]\AppData\Roaming and AppData\Local
writable without administrator privileges, making them prime locations for malware persistence without triggering UAC
C:\Windows\Temp and user Temp directories
common malware staging and drop zones. Executables running from Temp are almost always suspicious
Registry Run and RunOnce keys under HKLM and HKCU
are the most common Windows persistence locations (MITRE ATT&CK T1547.001
Autoruns from Sysinternals
the fastest tool for reviewing Windows persistence locations across Run keys, startup folders, scheduled tasks, and services
In PBQ process list questions the suspicious process is always the one running from an
unexpected path such as AppData, Temp, or the user's Downloads folder.
When told a process name looks legitimate, check
the file path first. The wrong path is the indicator
Linux uses a single unified directory tree rooted at /
The Filesystem Hierarchy Standard (FHS) defines the structure
/etc
contains critical system configuration files
/etc/passwd
user accounts
/etc/shadow
password hashes, readable only by root
/etc/sudoers
sudo privilege assignments
/etc/crontab
scheduled tasks used for persistence
/var/log
the primary log source
/var/log/auth.log (Debian/Ubuntu) and /var/log/secure (RHEL/CentOS)
capture authentication events
/var/log/audit/audit.log
captures kernel-level audit events via auditd
/tmp
world-writable and a common malware staging area
/dev/shm
an in-memory filesystem that enables fileless execution leaving no disk artifact
/proc
a virtual filesystem exposing live process information
/proc/[PID]/exe
points to a process's executable even if the file has been deleted from disk
A recently modified /etc/sudoers file during a breach window is
a critical finding. This is the Linux equivalent of a Registry Run key modification
Fileless malware on Linux executes from
/dev/shm; If a scenario describes malware with no file system evidence, /dev/shm and memory-resident execution are the answer
Every attack eventually becomes
a process
Process trees reveal
arent-child relationships that expose attacker behavior
lsass.exe
handles Windows authentication and is the primary target for credential dumping (T1003). It runs from System32, runs as SYSTEM, and never spawns child processes. Any deviation is a critical alert
svchost.exe
hosts Windows services. It should always have services.exe as its parent and run from System32
An svchost.exe with
an explorer.exe parent or running from AppData is malicious
On Linux, ____ manages services (PID 1)
systemd
Attackers create malicious systemd service units in ____ designed to blend with legitimate service names
/etc/systemd/system/
LOLBins (Living Off The Land Binaries)
legitimate OS tools abused for malicious activity. Windows examples include PowerShell, certutil.exe, and mshta.exe. Linux examples include curl, wget, and nc
For LOLBin questions, signature-based detection is insufficient. The correct answer will always involve
behavior-based detection combining the process with its network or file activity
Process analysis PBQs test three signals
unexpected path, unexpected parent process, and unexpected user context
Hardening is what you do at
intiial build
Configuration best practices
what you do continuously afterward to prevent and detect configuration drift
Group Policy enforces ______ across active directory
security configurations
Attackers who gain domain admin can modify
GPOs to disable Defender, disable logging, or add malicious startup scripts
AppLocker enforces
execution control based on path, publisher, or hash (user-mode enforced)
Windows Defender Application Control (WDAC) is
kernel-enforced and more resistant to bypass
is App Locker or WDAC the stronger control
WDAC
Critical Windows audit policies include
Audit Process Creation (required for Event ID 4688), Audit Logon Events, Audit Policy Change, and Audit Privilege Use
Default audit settings are insufficient
Vulnerability patching prioritization should combine
CVSS (severity score) with EPSS (probability of exploitation in the wild). CVSS score alone is insufficient for prioritization
Continuous configuration assessment using ______ detects drift before attackers can exploit it
Nessus, AWS Config, Azure Policy, or GCP Security Command Center
A host that stops generating Event ID 4688 during an investigation window is
actively suspicious, not just a logging gap. ttackers disable audit logging as an anti-forensic technique