NEWEST SANS FOR508 COMPLETE STUDY GUIDE
WITH GRADED SOLUTIONS
What drives the immediate eradication/remediation
call to arms? - Answer-Fear of losing data
data deemed as too valuable, risk too high.
Dwell Time - answer-The time an attacker has
remained undetected within a network. An
important metric to track as it directly correlates
with the ability of an attacker to accomplish their
objectives.
Breakout Time - answer-Time is takes an intruder
to begin moving laterally once they have an initial
foothold in the network.
Main Threat Actors - answer-APT (Nation State
Actors)
Organized Crime
Hacktivists
,NIST - answer-US National Institute for Standards
and Technology
Six-Step Incident Response Process - answer-1:
Preparation
2: Identification
3: Containment and Intelligence Development
4: Eradication and Remediation
5: Recovery
6: Follow-up
Six-Step - Preparation - answer-Incident response
methodologies emphasize preparation-not only
establishing a response capability so the
organization is ready to respond to incidents but
also preventing incidents by ensuring that systems,
networks, and applications are sufficiently secure.
Six-Step - Identificatoin - answer-Identification is
triggered by a suspicious event. This could be from
, a security appliance, a call to the help-desk, or the
result of something discovered via threat hunting.
Event validation should occur and a decision made
as to the severity of the finding (not valid events
lead to a full incident response). Once an incident
response has begun, this phase is used to better
understand the findings and begin scoping the
network for additional compromise.
Six Step - Containment and Intelligence
development - answer-In this phase, the goal is to
rapidly understand the adversary and begin crafting
a containment strategy. Responders must identify
the initial vulnerability or exploit, how the attackers
are maintaining persistence and laterally moving in
the network, and how command and control is
being accomplished. in conjunction with the
previous scoping phase, responders will work to
have a complete picture of the attack and often
implement changes to the environment to increase
host and network visibility. Threat intelligence is
one of the key products of the IP team during this
phase.
WITH GRADED SOLUTIONS
What drives the immediate eradication/remediation
call to arms? - Answer-Fear of losing data
data deemed as too valuable, risk too high.
Dwell Time - answer-The time an attacker has
remained undetected within a network. An
important metric to track as it directly correlates
with the ability of an attacker to accomplish their
objectives.
Breakout Time - answer-Time is takes an intruder
to begin moving laterally once they have an initial
foothold in the network.
Main Threat Actors - answer-APT (Nation State
Actors)
Organized Crime
Hacktivists
,NIST - answer-US National Institute for Standards
and Technology
Six-Step Incident Response Process - answer-1:
Preparation
2: Identification
3: Containment and Intelligence Development
4: Eradication and Remediation
5: Recovery
6: Follow-up
Six-Step - Preparation - answer-Incident response
methodologies emphasize preparation-not only
establishing a response capability so the
organization is ready to respond to incidents but
also preventing incidents by ensuring that systems,
networks, and applications are sufficiently secure.
Six-Step - Identificatoin - answer-Identification is
triggered by a suspicious event. This could be from
, a security appliance, a call to the help-desk, or the
result of something discovered via threat hunting.
Event validation should occur and a decision made
as to the severity of the finding (not valid events
lead to a full incident response). Once an incident
response has begun, this phase is used to better
understand the findings and begin scoping the
network for additional compromise.
Six Step - Containment and Intelligence
development - answer-In this phase, the goal is to
rapidly understand the adversary and begin crafting
a containment strategy. Responders must identify
the initial vulnerability or exploit, how the attackers
are maintaining persistence and laterally moving in
the network, and how command and control is
being accomplished. in conjunction with the
previous scoping phase, responders will work to
have a complete picture of the attack and often
implement changes to the environment to increase
host and network visibility. Threat intelligence is
one of the key products of the IP team during this
phase.