Font size
WorksheetsSecurity Operations Quiz
Total questions: 140
Worksheet time: 1hrs 25mins
The process of applying secure configurations (to reduce the attack surface) and locking down various hardware, communications systems and software.
Harding
Data Handling Model
Its own lifecycle as users create, use, share, and modify it.
Data Handling Model
Harding
Data Handling Model:
"The knowledge, is usually tacit knowledge at this point"
Creating
Storing
Using
Sharing
Data Handling Model:
"Or recording it in some fashion (makes it explicit)"
Storing
Using
Sharing
Archiving
Data Handling Model:
"The knowledge, may cause the information to be modified, supplemented or partially deleted"
Using
Sharing
Archiving
Destorying
Data Handling Model:
"The data with other users, a copy or by moving the data from one location to another
Sharing
Archiving
Destorying
Creating
Data Handling Model:
"The data when it is temporarily not needed"
Archiving
Destorying
Creating
Storing
Data Handling Model:
"The data when it is no longer needed"
Destroying
Creating
Storing
Using
Data Handling Practices:
"Dictate rules and restrictions about how that information can be used, stored and shared with others"
Classification
Labeling
Data Sensitivity Levels and Labels
Data Handling Practices:
"Security labels are part of implementing controls to protect classified information"
Labeling
Data Sensitivity Levels and Labels
Classification
Data Handling Practices:
"Otherwise mandated, organizations are free to create classification systems that best meet their own needs"
Data Sensitivity Levels and Labels
Labeling
Classification
Data Handling Practices:
"Compromise of data with this sensitivity label could possibly put the organization's future existence at risk"
Highly restricted
Moderately restricted
Low sensitivity/Internal Use Only
Unrestricted public data
Data Handling Practices:
"Compromise of data with this sensitivity label could lead to loss of temporary competitive advantaged loss of revenue or disruption of planned investments or activities"
Moderately restricted
Low sensitivity/Internal Use Only
Unrestricted public data
Highly restricted
Data Handling Practices:
"Compromise of data with this sensitivity label could cause minor disruptions, delays or impacts"
Low sensitivity/Internal Use Only
Unrestricted public data
Highly restricted
Moderately restricted
Data Handling Practices:
"As this data is already published, no harm can come from further dissemination or disclosure"
Unrestricted public data
Low sensitivity/Internal Use Only
Moderately restricted
Highly restricted
Data Handling Practices:
"Information and data should be kept only for as long as it is beneficial, no more and no less"
Retention
Destruction
Data Handling Practices:
"Are applicable both for hard copies and for electric data"
Data retention policies
Records retention policies
Data Handling Practices:
"Indicate how long an organization is required to maintain information and assets"
Records retention policies
Data retention policies
Data Handling Practices:
"Data that might be left on media after deleting is known as remanence and may be significant security concern"
Destruction
Retention
*Clearing the device or system
*Purging the device or system
*Physical destruction of the device or system
*In many routine operational environments
Destruction
Retention
The primary form of instrumentation that attempts to capture signals generated by events.
Logging
Logging and Monitoring the Health of the Information Environment
Robust logging
Log reviews
Is essential to identifying inefficient or improperly performing systems, detecting compromises and providing a record of how systems are used
Logging and Monitoring the Health of the Information Environment
Robust logging
Log reviews
Logging
Provide tools to effectively correlate information from diverse systems to fully understand the relationship between one activity and another
Robust logging
Log reviews
Logging
Logging and Monitoring the Health of the Information Environment
An essential function for identifying security incidents, policy violations, fraudulent activities and operational problems near the time of occurrence
Log reviews
Robust logging
Logging and Monitoring the Health of the Information Environment
Logging
Event Logging Best Practices:
"Refers to surveillance and assessment of all inbound communications traffic and access attempts."
Devices and Tools: Firewalls, Gateways, Remote authentication servers, IDS/IPS tools, SIEM solutions, Anti-malware solution.
Ingress Monitoring
Egress Monitoring
Event Logging Best Practices:
"Used to regulate data leaving the organization's IT environment.
Data loss prevention/Data leak protection: Email (content and attachments), Copy to portable media, File Transfer Protocol (FTP), Posting to web pages/websites, Applications/Application programming interfaces (APIs)
Egress Monitoring
Ingress Monitoring
Protects our personal and business transactions
Encryption
Cryptography
Used to protect information by keeping its meaning or content secret and making it unintelligible to someone who does not have a way to decrypt (unlock) that protected information
Cryptography
Encryption
Cryptographic solutions provide a range of services that can help achieve:
Confidentiality
Integrity
A process and discipline used to ensure that the only changes made to a system are those that have been authorized and validated.
Configuration Management
Inventory
Baselines
Updates
Configuration Management:
"Baseline identification of a system and all its components, interfaces and documentation"
i. Identification
ii. Baseline
iii. Change Control
iv. Verification and Audit
Configuration Management:
"A security minimum level of protection that can be used as a reference point"
ii. Baseline
iii. Change Control
iv. Verification and Audit
i. Identification
Configuration Management:
"An update process for requesting changes to a baseline, by means of making changes to one or more components in that baseline."
iii. Change Control
iv. Verification and Audit
ii. Baseline
i. Identification
Configuration Management:
"A regression and validation process, involving testing and analysis, to verify that nothing in the system was broken by a newly applied set of changes"
iv. Verification and Audit
iii. Change Control
ii. Baseline
i. Identification
Configuration Management:
"An audit process can validate that the currently in-use baseline matches the sum total of its initial baseline plus all approved changes applied in sequence."
iv. Verification and Audit
iii. Change Control
ii. Baseline
i. Identification
Is the 1st step in any asset management process.
Example: Catalog or Registry
Inventory
Baselines
Updates
Patches
Is a total inventory of all the system's components, hardware, software, data, administrative controls, documentation and user instructions
Baselines
Updates
Patches
Inventory
Must be acceptance tested to verify that newly installed (or repaired) functionality works as required
Updates
Patches
Baselines
Inventory
The challenge for the security professional is maintaining all patches
Patches
Updates
Baselines
Inventory
Common Security Policies:
"Appropriate use of data"
Data Handling Policy
Password Policy
Acceptable Use Policy (AUP)
Bring Your Own Device (BYOD)
Common Security Policies:
"Every organization should have a password policy in place that defines expectations of systems and users"
Password Policy
Acceptable Use Policy (AUP)
Bring Your Own Device (BYOD)
Privacy Policy
Common Security Policies:
"Defines acceptable use of the organization's network and computer systems and can help protect the organization from legal action"
Acceptable Use Policy (AUP)
Bring Your Own Device (BYOD)
Privacy Policy
Change Management Policy
Common Security Policies:
"An organization may allow workers to acquire equipment of their choosing and use personally owned equipment for business (and personal) use
Bring Your Own Device (BYOD)
Privacy Policy
Change Management Policy
Password Policy
Common Security Policies:
Understand and acknowledge that type of information and are made aware of the legal repercussions of handling such sensitive data"
Privacy Policy
Change Management Policy
Bring Your Own Device (BYOD)
Acceptable Use Policy (AUP)
Common Security Policies:
"The discipline of transitioning from the discipline of transitioning from the current state to a future state"
Change Management Policy
Privacy Policy
Bring Your Own Device (BYOD)
Acceptable Use Policy (AUP)
Change Management Components:
"All of the major change movement practices address a common set of core activities that state with a common set of core activities that start with a request for change"
Documentation
Approval
Rollback
Change Management Components:
"To the proper change authorization process based on risk and organizational practices"
Approval
Rollback
Documentation
Change Management Components:
"Depending upon the nature of the change, a variety of activities may need to be completed"
Rollback
Approval
Documentation
Purpose of (a) training: is to make sure everyone knows what is expected of them, based on responsibilities and accountabilities, and to find out if there is any carelessness or complacency that may pose a risk to the organization.
Learning activities that organizations use:
"The overall goal of education is to help learners improve their understanding of these ideas and their ability to relate them to their own experiences and apply that learning in useful ways"
Education
Training
Awareness
Learning activities that organizations use:
"Focuses on building proficiency in a specific set of skills or actions"
Training
Awareness
Education
Learning activities that organizations use:
"Activities that attract and engage the learner's attention by acquainting them with aspects of an issue, concern, problem or need"
Awareness
Training
Education
Security Awareness Training Examples:
Fire Safety
Phishing
Social Engineering
Password Protection
Encryption makes (a)
Transforms plaintext into ciphertext
Encryption
Decryption
Key
The password to the data
Key
Encryption
Decryption
Transforms ciphertext back into plaintext
Decryption
Key
Encryption
1) File encryption
2) Disk encryption
3) Device encryption
Protecting Data at Rest/Stored Data
Protecting Data in Transit/Data that's moving over a network
1) HTTPS (web)
2) Email
3) Mobile applications
4) VPN (network)
Protecting Data in Transit/Data that's moving over a network
Protecting Data at Rest/Stored Data
Symmetric shapes have identical halves
True
False
Symmetric vs. Asymmetric Cryptography:
In (a) encryption you encrypt and decrypt with the same shared secret key
Symmetric vs. Asymmetric Cryptography:
In (a) encryption you encrypt and decrypt with different keys from the same pair
Symmetric vs. Asymmetric Cryptography:
Asymmetric algorithms use keypairs where each user gets a __ key and a __ key
(a)
Symmetric vs. Asymmetric Cryptography:
The (a) key is freely shared
Symmetric vs. Asymmetric Cryptography:
The (a) key is kept secret
Symmetric vs. Asymmetric Cryptography:
Encrypt with the public key and decrypt with the (a) key
Keys used for asymmetric encryption and decryption must be from the same pair!
True
False
Symmetric vs. Asymmetric Cryptography:
Advanced Encryption Standard (AES) is (a)
Symmetric vs. Asymmetric Cryptography:
RSA algorithm is (a)
_ Functions: One-way functions that transform a variable length input into a unique, fixed-length output
(a)
*One-way functions can't be reversed
*The output of a hash function will always be the same length, regardless of the input size
*No two inputs to a hash function should produce the same output
Hash Function Characteristics
Hash Functions May Fail
Message Digest 5 (MD5)
*If they are reversible, or
*If they are not collision-resistant
Hash Functions May Fail
Message Digest 5 (MD5)
Hash Function Characteristics
*Ron Rivest created MD5 in 1991
*MD5 is the fifth in a series of hash functions
*Message digest is another term for hash
*MD5 produces 128-bit hashes
*MD5 is no longer secure
Message Digest 5 (MDS)
Hash Functions May Fail
Hash Function Characteristics
*Produces a 160-bit hash value
*Contains security flaws that render it insecure
SHA-1
SHA-2
SHA-3
*Consists of a family of six hash functions
*Produces output of 224, 256, 384, and 512 bits
*Uses a mathematically similar approach to SHA-1 and MD5
*Secure
SHA-2
SHA-3
SHA-1
*Designed to replace SHA-2
*Uses a completely different hash generation approach than SHA-2
*Produces hashes of user-selected fixed length
*Secure
SHA-3
SHA-2
SHA-1
*Created as an alternative to government-sponsored hash functions
*Produces 128, 160, 256, and 320-bit hashes
*Contains flaws in the 128-bit version
*Insecure
RIPEMD
HMAC
*Hash-Based Message Authentication Code
*Combines symmetric cryptography and hashing
*Provides authentication and integrity
*Create and verify message authentication code by using a secret key in conjunction with a hash function
*Secure
HMAC
RIPEMD
(a) Functions are used with asymmetric cryptograph for digital signatures and digital certificates
The (a) lifecycle explains the different stages of data in the cloud.
Data Lifecycle:
The organization (a) new data, either in the cloud or in an on-premises system
Data Lifecycle:
Data is moved into a (a) repository for retention and later use
Data Lifecycle:
Define: Data is viewed and/or processed by individuals and systems
(a)
Data Lifecycle:
Data is (a) with other employees, customers, and partners
Define: Data is moved from active storage to long-term storage repositories
(a)
Data Lifecycle:
Data is securely (a) when no longer needed
Is essential to preventing reconstruction
Data destruction
Data classification policies
Assign information into categories, known as classifications, that determine storage, handling, and access requirements
Data classification policies
Data destruction
*Clearing overwrites sensitive information to frustrate casual analysis
*Purging uses more advanced techniques to frustrate laboratory analysis
*Destroying completely obliterates the media through shredding, pulverization, melting, or burning
Data Sanitization Techniques
Different options to disposal
*Shredding
*Pulping
*Burning
Different options to disposal
Data Sanitization Techniques
Third-party services offer (a) capabilities
The stages of the lifecycle do not always occur in the same order
True
False
*Sensitivity of information
*Criticality of information
Assign Classifications Based Upon
Classification Levels
Military Classification - Top Secret - Secret - Confidential - Unclassified
Business Classification - Highly Sensitive - Sensitive - Internal - Public
Classification Levels
Assign Classifications Based Upon
Classification guides other security decisions
True
False
When an organization classifies information:
"Identify sensitive information"
Labeling Requirements
Classificaton
Types of information classified by external groups:
"Traceable to a specific person"
Personally Identifiable Information (PII)
Protected Health Information (PHI)
Payment Card Information (PCI)
Types of information classified by external groups:
"Covered by HIPAA"
Protected Health Information (PHI)
Payment Card Information (PCI)
Personally Identifiable Information (PII)
Types of information classified by external groups:
"Covered by PCI DSS"
Payment Card Information (PCI)
Protected Health Information (PHI)
Personally Identifiable Information (PII)
Data Classification:
Securely (a) of information when no longer needed
Are a crucial tools for security professionals
Logs
Classification
Achieve important objectives:
"Who cause the event?"
Also known as Identity Attribution
Example: A specific person, A computer's IP address, A geographic location
Accountability
Traceability
Auditability
Achieve important objectives:
"Uncover all other related events"
Example: Investigating events
Traceability
Auditability
Accountability
Achieve important objectives:
"Provide clear documentation of the events"
Auditability
Traceability
Accountability
Systems generate far too many (a) records for manual analysis
Artificial (a) can help solve security data overload
1) Central, secure collection point for logs
*All systems send log entries directly to the SIEM
2) Source of Artificial Intelligence (AI)
Security Information and Event Management (SIEM)
Artificial Intelligence (AI)
(a) have access to log entries from across the organization
SIEM:
"Triggers the initial alert"
Intrusion Detection System
Firewall Log
Web Server Log
Database Log
SIEM:
1) Suspicious connection
Firewall Log
Web Server Log
Database Log
Router Log
SIEM:
2) SQL injection attack
Web Server Log
Database Log
Router Log
Firewall Log
SIEM:
3) Large query
Database Log
Router Log
Firewall Log
Web Server Log
SIEM:
4) Large outbound data flow
Router Log
Database Log
Web Server Log
Firewall Log
(a) provide security professionals with a valuable tool, Correlating Security Event Information
Social (a) presents serious risks to cybersecurity
Manipulating people into divulging information or performing an action that undermines security
Social Engineering
Authority and Trust
Intimidation
Consensus/Social Proof
*Authority
*Intimidation
*Consensus
*Scarcity
*Urgency
*Familiarity
Social Engineering
Education
Social Engineering:
People defer to authority
Authority
Intimidation
Consensus/Social Proof
Scarcity
Social Engineering:
Scaring people
Intimidation
Consensus/Social Proof
Scarcity
Urgency
Social Engineering:
The herd mentality
Example: Riots
Consensus/Social Proof
Scarcity
Urgency
Familiarity/Liking
Social Engineering:
Getting the last one
Example: Releases a new product
Scarcity
Urgency
Familiarity/Liking
Intimidation
Social Engineering:
Time is running out
Urgency
Familiarity/Liking
Scarcity
Consensus/Social Proof
Social Engineering:
We say yes to people we like
Familiarity/Liking
Urgency
Authority and Trust
Intimidation
Education is the solution
True
False
Impersonation Attacks:
Unsolicited commercial email
Spam
Phishing
Spear Phishing
Whaling
Impersonation Attacks:
Stealing credentials
Phishing
Spear Phishing
Whaling
Pharming
Impersonation Attacks:
Targeted attack
Spear Phishing
Whaling
Pharming
Vishing
Impersonation Attacks:
Targeted attacks on executives
Whaling
Pharming
Vishing
Smishing and SPIM
Impersonation Attacks:
Using fake websites
Pharming
Vishing
Smishing and SPIM
Spoofing
Impersonation Attacks:
Voice phishing
Vishing
Smishing and SPIM
Spoofing
Spam
Impersonation Attacks:
SMS and IM spam
Smishing and SPIM
Spoofing
Spam
Phishing
Impersonation Attacks:
Faking and identity
Spoofing
Spam
Phishing
Spear Phishing
Security training programs help (a) users about risks
Security Education Programs:
1) Provides users with the knowledge they need to protect the organization's security
Security Training
Security Awareness
Security Education Programs:
2) Keeps the lessons learns learned during security training top of mind for employees
Security Awareness
Security Training
*Instruction in on-site classes
*Instruction with orientations
*Education through online computer-based training providers
*Participation in vendor-provided classroom training
Security Training Methods
Use Diversity of Training Techniques
Training Frequency
*Phishing simulations
*Gamification
*Capture the Flag exercises
Use a Diversity of Training Techniques
Training Frequency
Security Training Methods
Customize training based upon (a) roles
*Initial training for new employees
*Update training for employees with new roles
*Refresher training on a annual basis
*Awareness efforts throughout the year
Training Frequency
Use a Diversity of Training Techniques
Security Training Methods
Review training materials regularly to ensure relevance
True
False
