A WITH COMPLETE QUESTIONS AND CORRECT
DETAILED ANSWERSLATEST UPDATE
Save
Practice questions for this set
Learn 1 /7 Study with Learn
-Prevent or slow additional access during monitoring and collection phase
-Full-scale host/network monitoring
-Data decoy
-Bit mangling
Traffic shaping
-Adversary network segmentation "AVOID PLAYING YOUR HAND"
Choose an answer
1 Dwell Time 2 Whack-a-mole
3 Six-Step Incident Response Process 4 Containment/Active Defense
, Don't know?
Terms in this set (65)
Dwell Time The time an attacker has remained undetected
within a network. An important metric to track as it
directly correlates with the ability of an attacker to
accomplish their objectives.
Breakout Time Time is takes an intruder to begin moving laterally
once they have an initial foothold in the network.
Main Threat Actors APT (Nation State Actors)
Organized Crime
Hacktivists
NIST US National Institute for Standards and Technology
Six-Step Incident Response Process 1: Preparation
2: Identification
3: Containment and Intelligence Development
4: Eradication and Remediation
5: Recovery
6: Follow-up
Six-Step - Preparation Incident response methodologies emphasize
preparation-not only establishing a response
capability so the organization is ready to respond
to incidents but also preventing incidents by
ensuring that systems, networks, and applications
are sufficiently secure.