Reconnaissance
Weaponization
Delivery
Exploitation
Installation
Command & Control
Act on Objective - Answers Cyber-Attack Lifestyle Stages
Outside of data center
Gather information about target - Answers Reconnaissance
Outside of data center
Prepare attack method and malware - Answers Weaponization
Transition from outside to inside data center
Transfer malware to data center - Answers Delivery
Inside data center
Malware attacks software vulnerability - Answers Exploitation
Inside data center
Install custom malware tools (rootkit or RAT) - Answers Installation
"C2"
Inside data center
Establish communication channel to control server - Answers Command & Control
A tool that obtains the highest level of privilege on a device, sometimes used intentionally by a mobile
device owner to override the protections installed by the service provider. - Answers Rootkit
A remote administration tool maliciously installed as a Trojan horse to give a remote user some level of
control of the infected system. Important part of a botnet.
,• Symptoms: Usually undetectable until activated. System damage, data loss.
• Action: Restore system from backups. - Answers Remote Access Trojan (RAT)
Attacks that use readily available tools with little or no customization. - Answers Commodity Threats
A sophisticated, possibly long-running computer hack that is perpetrated by large, well-funded
organizations such as governments - Answers Advanced Persistent Threat (APT)
Attack floods a network or server with service requests to prevent legitimate users' access to the system
- Answers Denial of Service (DoS)
Ingress
Slowpath
Fastpath
Application Identification
Content Inspection
Egress - Answers Firewall Packet Flow States
Receives packets
Detect and drop packets with errors
Detect and block pre-session, packet-based reconnaissance and DoS attack - Answers Ingress
Establishes new sessions
Check FW session limits
Session-based DoS protection
Check and apply Security policy rules - Answers Slowpath
Performs NAT and decryption
Session-based DoS protection
Check and apply Security policy rules - Answers Fastpath
Check and apply Security policy rules
Control by application rather than port and protocol - Answers Application Identification
Performs threat inspection and takes action prescribed in Security Profiles
, Re-encrypt decrypted traffic - Answers Content Inspection
Implements QoS policy
Forward packets to next destination - Answers Egress
In which cloud computing service model does a provider's applications run on a cloud infrastructure and
the consumer does not manage or control the underlying infrastructure? Choose 1:
a. platform as a service (Paas)
b. infrastructure as a service (IaaS)
c. software as a service (SaaS)
d. public cloud - Answers c. software as a service (SaaS)
Business intelligence (BI) software consists of tools and techniques used to surface large amounts of raw
unstructured data to perform a variety of tasks including data mining, event processing and predictive
analytics. T/F? - Answers True
The process in which end users find personal technology and apps that are more powerful or capable,
more convenient, less expensive, quicker to install and easier to use than enterprise IT solutions is
known as consumerization. T/F? - Answers True
An organization can be compliant with all applicable security and privacy regulations for its industry, yet
still not be secure. T/F? - Answers True
The US law that establishes national standards to protect individuals' medical records and other health
info is known as the _____ - Answers HIPPA
What are lessons or common themes that can be derived from the Target, Home Depot, Anthem, OPM,
Yahoo! and Equifax cyber attack examples? - Answers Discussion...
Most cyber attacks today are perpetrated by internal threat actors such as malicious employees
engaging in corporate espionage. T/F? - Answers False. External threat answers have accounted for the
majority of data breaches over the past five years. According to Verizon's 2018 Data Breach
Investigations Report, internal threat actors are responsible for about 28 percent of reported data
breaches.
Describe the different motivations of various adversaries including cybercriminals, cyberterrorists, state-
sponsored organizations and hacktivists. - Answers Discussion...
The Cyber-Attack Lifecycle is a five-step process that an attacker goes through to attack a network. T/F? -
Answers False. The Cyber-Attack Lifecycle is a seven-step process.
List and describe the steps of the Cyber-Attack Lifecycle - Answers 1. Reconnaissance